CVE-2025-6544 | h2oai h2o-3 up to 3.46.7 JDBC Connection deserialization (EUVD-2025-30380)
A vulnerability categorized as critical has been discovered in h2oai h2o-3 up to 3.46.7. This impacts an unknown function of the component JDBC Connection Handler. The manipulation results in deserialization.
This vulnerability was named CVE-2025-6544. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.