Junglewise Threat Intelligence

CVE-2024-5986: PYSEC-2026-353 - H2O has an External Control of File Name or Path vulnerability

CVE-2024-5986 · Severity: low · CVSS 3 · Published 2026-06-29

Technologies: ai.h2o:h2o-core (Maven), h2o (PyPI). Vendors: Maven, PyPI.

Executive brief

H2O has an External Control of File Name or Path vulnerability

Affected products

  • Maven ai.h2o:h2o-core
  • PyPI h2o

Related threats