Deserialization Vulnerability in H2 JDBC Driver of h2oai h2o-3
CVE-2025-10769
Key Information:
Badges
What is CVE-2025-10769?
A deserialization vulnerability has been identified in the H2 JDBC Driver component of h2oai h2o-3, specifically within an unspecified function of the file /99/ImportSQLTable. This flaw arises from improper handling of the connection_url argument, enabling attackers to craft malicious inputs that may lead to unintended code execution and system compromise. The vulnerability can be exploited remotely, posing a substantial threat to applications utilizing affected versions of h2o-3. The vendor was alerted regarding this issue but failed to provide a response.
Affected Version(s)
h2o-3 3.46.08
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved