Release notes
The version history for H2O-3 Secure. Binaries are licensed, but this history is public, so you can see what shipped in each release (including the security fixes) and tell what's in your version at a glance.
3.46.0.10 (March 12, 2026)
Highlights
- Control-variable MOJO support (regression and binomial)
- Added R 4.5 support
- GAM / GLM / ModelSelection fixes
Security fixes
- log4j
CVE-2025-68161 - jackson-databind
GHSA-72hv-8253-57qq - FedRAMP remediation
- Blocked vulnerable PostgreSQL JDBC params
API and compatibility
- Dropped Python 3.6
- Added R 4.5
3.46.0.9 (November 24, 2025)
Highlights
- Control variables in GLM (regression and binomial)
- Fixed GLM AIC calculation
- Fixed
relevelwith special characters
Security fixes
CVE-2024-7768(H2O-3)
3.46.0.8 (October 8, 2025)
Highlights
- CoxPH MOJOs from 3.32.x now uploadable
- Fixed XGBoost MOJO scoring with offset column
- GLM grid accepts
lambda_alias
Security fixes
- MySQL JDBC
CVE-2025-6544/CVE-2025-5662 - commons-beanutils
CVE-2025-48734 - commons-lang3
CVE-2024-48924 - nimbus-jose-jwt
CVE-2025-53864 - protobuf-java
CVE-2024-7254
API and compatibility
- GLM grid:
lambda_alias - Docker image no longer runs as root
3.46.0.7 (March 27, 2025)
Highlights
- Removed Hadoop HDP packages (vendor EOL)
- Fixed
uplift_drfdemo notebook
Security fixes
- mina-core
CVE-2024-52046
API and compatibility
- Removed Hadoop HDP packages
3.46.0.6 (January 11, 2025)
Highlights
- HGLM is now a standalone algorithm (Gaussian)
- Adjustable Parquet import timezone
- Constrained-GLM fixes
Security fixes
- JDBC param validation
CVE-2024-8862 - avro 1.11.4
CVE-2024-47561 - commons-collections
sonatype-2024-3350 CVE-2024-5979(AstRunTool crash)
API and compatibility
- HGLM moved from a parameter to a standalone algorithm
3.46.0.5 (August 28, 2024)
Highlights
- Load data from Snowflake via JDBC
- ModelSelection categorical-predictor fix
- MOJO for Isolation Forest and Extended Isolation Forest
Security fixes
- jackson-databind 2.17.2
sonatype-2024-0171 - dnsjava 3.6.0
CVE-2024-25638
3.46.0.4 (July 9, 2024)
Highlights
- Security-focused maintenance release
- User-guide updates (clients, data ingest)
Security fixes
- jackson-databind
PRISMA-2023-0067
3.46.0.3 (June 11, 2024)
Highlights
- WebSocket support in
steam.jar - Auto multi-thread for
as_data_frame - Explainability plotting fixes
API and compatibility
as_data_framecan auto-enable multi-threading
3.46.0.2 (May 13, 2024)
Highlights
- ZSTD compression support
- Linear constraints in the GLM toolbox
- XGBoost
gblinearparameter support
Security fixes
- aws-java-sdk
CVE-2024-21634 - commons-configuration2
CVE-2024-29131
API and compatibility
- Removed
custom_metric_funcfrom ModelSelection
3.46.0.1 (March 13, 2024)
Highlights
- MLflow flavors for MOJOs / POJOs
- Custom-metric support for XGBoost
- MLI for Uplift DRF (PDP and variable importance)
- GLM loglikelihood and AIC for built models
Security fixes
- POJO import disabled by default
CVE-2023-6016 - jackson-databind
CVE-2023-35116 - nimbus-jose-jwt
SNYK-...-6247633 - Filesystem access filter
CVE-2023-6038 - commons-compress
CVE-2024-26308
API and compatibility
- Java property to disable auto POJO import
- Filesystem read/write filter option
3.44.0.3 (December 20, 2023)
Highlights
- AdaBoost deep-learning weak learner
- Scoring history for Extended Isolation Forest
- polars-based DataFrame transforms
Security fixes
- nanohttpd replaced
CVE-2022-21230
API and compatibility
H2OFrameconstructor accepts an existingH2OFrame
3.44.0.2 (November 8, 2023)
Highlights
- Binomial
thresholds_and_metric_scoresfix - CoxPH learning-curve plot fix
- Friedman–Popescu H-statistic docs
Security fixes
- jython / jnr-posix
CWE-416
API and compatibility
- Renamed
partial_plotdataparameter toframe
This page covers the most recent releases. For the version history of earlier releases, contact H2O support.
- Submit and view feedback for this page
- Send feedback about H2O-3 Secure to cloud-feedback@h2o.ai