Release notes
The version history for H2O-3 Secure. Binaries are licensed, but this history is public, so you can see what shipped in each release (including the security fixes) and tell what's in your version at a glance.
3.48.0.1 (September 29, 2026)
3.48.0.1 is the first H2O-3 Secure release on the 3.48 line. It follows 3.46.0.11. Contact enterprise@h2o.ai for the download link.
Highlights
- Python 3.12, 3.13, and 3.14. The Python client now supports Python 3.7
to 3.14, and the
pipand Conda packages support the whole range. See the requirements. - Flow removed. The standalone, minimal, and Steam assemblies no longer include the Flow web UI.
- GLM offset removal.
remove_offset_effectsnow works with cross-validation and with interactions.
Breaking changes
- Flow no longer opens in the browser. On the standalone, minimal, and Steam assemblies, the H2O-3 Secure address shows a status message instead. Use the Python or R client.
H2OFrame.as_data_frame()andh2o.as_list()treat only empty fields as NA by default. Strings such as"NA"or"NULL"now stay as values. To get the previous behavior, passna_values=["", "NA", "NULL", "NaN", "None", "N/A", "#N/A"].H2OFrame.apply()raises aValueErrorfor a lambda that calls a free function with arguments. For example,lambda x: some_func(x, 2)now fails. Earlier versions silently dropped the arguments. Use a method on the frame instead.
New features and improvements
- GLM:
remove_offset_effectsnow works with cross-validation and with interactions. - H2O-3 Secure can send anonymous usage telemetry. It's opt-in and off by default.
H2OFrame.as_data_frame()andh2o.as_list()gain anna_valuesargument.H2OKFoldandH2OStratifiedKFoldsupport the scikit-learn splitter API (split()andget_n_splits()).iter_h2oframes()returns training and test splits without pulling the data into Python.convert_H2OXGBoostParams_2_XGBoostParams()defaultsbase_scoreto0.5, matching the XGBoost bundled with H2O-3 Secure.- A Chainguard-based Docker image is available.
Bug fixes
- GAM: the
splines_non_negativeparameter now shows in the model output.
Security fixes
- jackson-databind 2.18.10
CVE-2026-54512/CVE-2026-54513/CVE-2026-54514/CVE-2026-54515/CVE-2026-68497/sonatype-2026-005959 - commons-configuration2 2.15.0
CVE-2026-45205 - log4j 2.25.5
CVE-2026-49844 - mina-core 2.2.9
CVE-2026-47065
Licensing
h2o.jar,h2o-genmodel.jar, and exported MOJOs and POJOs are under the current H2O.ai end-user license agreement (EULA). The Python, R, and Conda packages declare both Apache-2.0 and the EULA. The client-only packages stay Apache-2.0.
Documentation
- H2O-3 Secure now has its own documentation site.
- New pages cover the deployment model, telemetry, algorithms, and the Python API.
- The PCA page notes that
use_all_factor_levelsisn't gridable. - The custom metric page has an example that defines a metric from a math formula.
3.46.0.12 (August 12, 2026)
3.46.0.12 is an OSS-only variant of 3.46.0.11 and isn't part of H2O-3 Secure. Only its telemetry carries forward into 3.48.0.1.
Highlights
- Opt-in anonymous usage telemetry (Python, R, JVM)
- In-product messaging that tells OSS and Secure apart
- MOJO and POJO extraction blocked in the OSS build
3.46.0.11 (May 21, 2026)
Highlights
- GLM: remove offset effects, with MOJO support
- Fixed GLM standard error calculation
- Fixed nondeterminism in GAM grid search
- R
shap_summary_plotfixes
Security fixes
- log4j
CVE-2026-34477/CVE-2026-34478/CVE-2026-34479/CVE-2026-34480 - mina-core
CVE-2026-41409/CVE-2026-42778/CVE-2026-42779
3.46.0.10 (March 12, 2026)
Highlights
- Control-variable MOJO support (regression and binomial)
- Added R 4.5 support
- GAM / GLM / ModelSelection fixes
Security fixes
- log4j
CVE-2025-68161 - jackson-databind
GHSA-72hv-8253-57qq - FedRAMP remediation
- Blocked vulnerable PostgreSQL JDBC params
API and compatibility
- Dropped Python 3.6
- Added R 4.5
3.46.0.9 (November 24, 2025)
Highlights
- Control variables in GLM (regression and binomial)
- Fixed GLM AIC calculation
- Fixed
relevelwith special characters
Security fixes
CVE-2024-7768(H2O-3)
3.46.0.8 (October 8, 2025)
Highlights
- CoxPH MOJOs from 3.32.x now uploadable
- Fixed XGBoost MOJO scoring with offset column
- GLM grid accepts
lambda_alias
Security fixes
- MySQL JDBC
CVE-2025-6544/CVE-2025-5662 - commons-beanutils
CVE-2025-48734 - commons-lang3
CVE-2024-48924 - nimbus-jose-jwt
CVE-2025-53864 - protobuf-java
CVE-2024-7254
API and compatibility
- GLM grid:
lambda_alias - Docker image no longer runs as root
3.46.0.7 (March 27, 2025)
Highlights
- Removed Hadoop HDP packages (vendor EOL)
- Fixed
uplift_drfdemo notebook
Security fixes
- mina-core
CVE-2024-52046
API and compatibility
- Removed Hadoop HDP packages
3.46.0.6 (January 11, 2025)
Highlights
- HGLM is now a standalone algorithm (Gaussian)
- Adjustable Parquet import timezone
- Constrained-GLM fixes
Security fixes
- JDBC param validation
CVE-2024-8862 - avro 1.11.4
CVE-2024-47561 - commons-collections
sonatype-2024-3350 CVE-2024-5979(AstRunTool crash)
API and compatibility
- HGLM moved from a parameter to a standalone algorithm
3.46.0.5 (August 28, 2024)
Highlights
- Load data from Snowflake via JDBC
- ModelSelection categorical-predictor fix
- MOJO for Isolation Forest and Extended Isolation Forest
Security fixes
- jackson-databind 2.17.2
sonatype-2024-0171 - dnsjava 3.6.0
CVE-2024-25638
3.46.0.4 (July 9, 2024)
Highlights
- Security-focused maintenance release
- User-guide updates (clients, data ingest)
Security fixes
- jackson-databind
PRISMA-2023-0067
3.46.0.3 (June 11, 2024)
Highlights
- WebSocket support in
steam.jar - Auto multi-thread for
as_data_frame - Explainability plotting fixes
API and compatibility
as_data_framecan auto-enable multi-threading
3.46.0.2 (May 13, 2024)
Highlights
- ZSTD compression support
- Linear constraints in the GLM toolbox
- XGBoost
gblinearparameter support
Security fixes
- aws-java-sdk
CVE-2024-21634 - commons-configuration2
CVE-2024-29131
API and compatibility
- Removed
custom_metric_funcfrom ModelSelection
3.46.0.1 (March 13, 2024)
Highlights
- MLflow flavors for MOJOs / POJOs
- Custom-metric support for XGBoost
- MLI for Uplift DRF (PDP and variable importance)
- GLM loglikelihood and AIC for built models
Security fixes
- POJO import disabled by default
CVE-2023-6016 - jackson-databind
CVE-2023-35116 - nimbus-jose-jwt
SNYK-...-6247633 - Filesystem access filter
CVE-2023-6038 - commons-compress
CVE-2024-26308
API and compatibility
- Java property to disable auto POJO import
- Filesystem read/write filter option
3.44.0.3 (December 20, 2023)
Highlights
- AdaBoost deep-learning weak learner
- Scoring history for Extended Isolation Forest
- polars-based DataFrame transforms
Security fixes
- nanohttpd replaced
CVE-2022-21230
API and compatibility
H2OFrameconstructor accepts an existingH2OFrame
3.44.0.2 (November 8, 2023)
Highlights
- Binomial
thresholds_and_metric_scoresfix - CoxPH learning-curve plot fix
- Friedman–Popescu H-statistic docs
Security fixes
- jython / jnr-posix
CWE-416
API and compatibility
- Renamed
partial_plotdataparameter toframe
This page covers the most recent releases. For the version history of earlier releases, contact H2O support.
- Submit and view feedback for this page
- Send feedback about H2O-3 Secure to cloud-feedback@h2o.ai