Skip to main content

Release notes

The version history for H2O-3 Secure. Binaries are licensed, but this history is public, so you can see what shipped in each release (including the security fixes) and tell what's in your version at a glance.

3.48.0.1 (September 29, 2026)​

3.48.0.1 is the first H2O-3 Secure release on the 3.48 line. It follows 3.46.0.11. Contact enterprise@h2o.ai for the download link.

Highlights

  • Python 3.12, 3.13, and 3.14. The Python client now supports Python 3.7 to 3.14, and the pip and Conda packages support the whole range. See the requirements.
  • Flow removed. The standalone, minimal, and Steam assemblies no longer include the Flow web UI.
  • GLM offset removal. remove_offset_effects now works with cross-validation and with interactions.

Breaking changes

  • Flow no longer opens in the browser. On the standalone, minimal, and Steam assemblies, the H2O-3 Secure address shows a status message instead. Use the Python or R client.
  • H2OFrame.as_data_frame() and h2o.as_list() treat only empty fields as NA by default. Strings such as "NA" or "NULL" now stay as values. To get the previous behavior, pass na_values=["", "NA", "NULL", "NaN", "None", "N/A", "#N/A"].
  • H2OFrame.apply() raises a ValueError for a lambda that calls a free function with arguments. For example, lambda x: some_func(x, 2) now fails. Earlier versions silently dropped the arguments. Use a method on the frame instead.

New features and improvements

  • GLM: remove_offset_effects now works with cross-validation and with interactions.
  • H2O-3 Secure can send anonymous usage telemetry. It's opt-in and off by default.
  • H2OFrame.as_data_frame() and h2o.as_list() gain an na_values argument.
  • H2OKFold and H2OStratifiedKFold support the scikit-learn splitter API (split() and get_n_splits()). iter_h2oframes() returns training and test splits without pulling the data into Python.
  • convert_H2OXGBoostParams_2_XGBoostParams() defaults base_score to 0.5, matching the XGBoost bundled with H2O-3 Secure.
  • A Chainguard-based Docker image is available.

Bug fixes

  • GAM: the splines_non_negative parameter now shows in the model output.

Security fixes

  • jackson-databind 2.18.10 CVE-2026-54512 / CVE-2026-54513 / CVE-2026-54514 / CVE-2026-54515 / CVE-2026-68497 / sonatype-2026-005959
  • commons-configuration2 2.15.0 CVE-2026-45205
  • log4j 2.25.5 CVE-2026-49844
  • mina-core 2.2.9 CVE-2026-47065

Licensing

  • h2o.jar, h2o-genmodel.jar, and exported MOJOs and POJOs are under the current H2O.ai end-user license agreement (EULA). The Python, R, and Conda packages declare both Apache-2.0 and the EULA. The client-only packages stay Apache-2.0.

Documentation

3.46.0.12 (August 12, 2026)​

note

3.46.0.12 is an OSS-only variant of 3.46.0.11 and isn't part of H2O-3 Secure. Only its telemetry carries forward into 3.48.0.1.

Highlights

  • Opt-in anonymous usage telemetry (Python, R, JVM)
  • In-product messaging that tells OSS and Secure apart
  • MOJO and POJO extraction blocked in the OSS build

3.46.0.11 (May 21, 2026)​

Highlights

  • GLM: remove offset effects, with MOJO support
  • Fixed GLM standard error calculation
  • Fixed nondeterminism in GAM grid search
  • R shap_summary_plot fixes

Security fixes

  • log4j CVE-2026-34477 / CVE-2026-34478 / CVE-2026-34479 / CVE-2026-34480
  • mina-core CVE-2026-41409 / CVE-2026-42778 / CVE-2026-42779

3.46.0.10 (March 12, 2026)​

Highlights

  • Control-variable MOJO support (regression and binomial)
  • Added R 4.5 support
  • GAM / GLM / ModelSelection fixes

Security fixes

  • log4j CVE-2025-68161
  • jackson-databind GHSA-72hv-8253-57qq
  • FedRAMP remediation
  • Blocked vulnerable PostgreSQL JDBC params

API and compatibility

  • Dropped Python 3.6
  • Added R 4.5

3.46.0.9 (November 24, 2025)​

Highlights

  • Control variables in GLM (regression and binomial)
  • Fixed GLM AIC calculation
  • Fixed relevel with special characters

Security fixes

  • CVE-2024-7768 (H2O-3)

3.46.0.8 (October 8, 2025)​

Highlights

  • CoxPH MOJOs from 3.32.x now uploadable
  • Fixed XGBoost MOJO scoring with offset column
  • GLM grid accepts lambda_ alias

Security fixes

  • MySQL JDBC CVE-2025-6544 / CVE-2025-5662
  • commons-beanutils CVE-2025-48734
  • commons-lang3 CVE-2024-48924
  • nimbus-jose-jwt CVE-2025-53864
  • protobuf-java CVE-2024-7254

API and compatibility

  • GLM grid: lambda_ alias
  • Docker image no longer runs as root

3.46.0.7 (March 27, 2025)​

Highlights

  • Removed Hadoop HDP packages (vendor EOL)
  • Fixed uplift_drf demo notebook

Security fixes

  • mina-core CVE-2024-52046

API and compatibility

  • Removed Hadoop HDP packages

3.46.0.6 (January 11, 2025)​

Highlights

  • HGLM is now a standalone algorithm (Gaussian)
  • Adjustable Parquet import timezone
  • Constrained-GLM fixes

Security fixes

  • JDBC param validation CVE-2024-8862
  • avro 1.11.4 CVE-2024-47561
  • commons-collections sonatype-2024-3350
  • CVE-2024-5979 (AstRunTool crash)

API and compatibility

  • HGLM moved from a parameter to a standalone algorithm

3.46.0.5 (August 28, 2024)​

Highlights

  • Load data from Snowflake via JDBC
  • ModelSelection categorical-predictor fix
  • MOJO for Isolation Forest and Extended Isolation Forest

Security fixes

  • jackson-databind 2.17.2 sonatype-2024-0171
  • dnsjava 3.6.0 CVE-2024-25638

3.46.0.4 (July 9, 2024)​

Highlights

  • Security-focused maintenance release
  • User-guide updates (clients, data ingest)

Security fixes

  • jackson-databind PRISMA-2023-0067

3.46.0.3 (June 11, 2024)​

Highlights

  • WebSocket support in steam.jar
  • Auto multi-thread for as_data_frame
  • Explainability plotting fixes

API and compatibility

  • as_data_frame can auto-enable multi-threading

3.46.0.2 (May 13, 2024)​

Highlights

  • ZSTD compression support
  • Linear constraints in the GLM toolbox
  • XGBoost gblinear parameter support

Security fixes

  • aws-java-sdk CVE-2024-21634
  • commons-configuration2 CVE-2024-29131

API and compatibility

  • Removed custom_metric_func from ModelSelection

3.46.0.1 (March 13, 2024)​

Highlights

  • MLflow flavors for MOJOs / POJOs
  • Custom-metric support for XGBoost
  • MLI for Uplift DRF (PDP and variable importance)
  • GLM loglikelihood and AIC for built models

Security fixes

  • POJO import disabled by default CVE-2023-6016
  • jackson-databind CVE-2023-35116
  • nimbus-jose-jwt SNYK-...-6247633
  • Filesystem access filter CVE-2023-6038
  • commons-compress CVE-2024-26308

API and compatibility

  • Java property to disable auto POJO import
  • Filesystem read/write filter option

3.44.0.3 (December 20, 2023)​

Highlights

  • AdaBoost deep-learning weak learner
  • Scoring history for Extended Isolation Forest
  • polars-based DataFrame transforms

Security fixes

  • nanohttpd replaced CVE-2022-21230

API and compatibility

  • H2OFrame constructor accepts an existing H2OFrame

3.44.0.2 (November 8, 2023)​

Highlights

  • Binomial thresholds_and_metric_scores fix
  • CoxPH learning-curve plot fix
  • Friedman–Popescu H-statistic docs

Security fixes

  • jython / jnr-posix CWE-416

API and compatibility

  • Renamed partial_plot data parameter to frame

This page covers the most recent releases. For the version history of earlier releases, contact H2O support.


Feedback