H2O.ai · Vulnerability Disclosure

H2O Ai Vulnerability Disclosure

Vulnerability disclosure

H2O.ai runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyArtificial IntelligenceMachine LearningMLOpsGenerative AILarge Language ModelsRetrieval Augmented GenerationData ScienceModel DeploymentAI AgentsEnterprise AI
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Contact
security@h2o.ai
Contact
sesecurity@h2o.ai

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-04'
method: searched
probe: false
probe_note: >-
  0-working/probe-security-programs.py returned vdp=none — /.well-known/security.txt is a
  404 on every H2O.ai host, and both h2o.ai/security and trust.h2o.ai render client-side so
  the probe's keyword check on raw HTML found nothing. The findings below were read from the
  rendered pages on 2026-08-04.
security_txt:
  published: false
  probed:
  - {url: 'https://h2o.ai/.well-known/security.txt', http_status: 404}
  - {url: 'https://docs.h2o.ai/.well-known/security.txt', http_status: 404}
  - {url: 'https://h2ogpte.genai.h2o.ai/.well-known/security.txt', http_status: 200,
     result: html-catchall, valid: false}
policy:
- https://h2o.ai/security/
- https://h2o.ai/security/report-vulnerability
contact:
- security@h2o.ai
- sesecurity@h2o.ai
bug_bounty:
  program: null
  platform: null
  note: >-
    No HackerOne, Bugcrowd or Intigriti program was found for H2O.ai. Reporting is via the
    intake page at h2o.ai/security/report-vulnerability and the Trust Center contacts.
advisories:
  url: https://h2o.ai/security/bulletins
  description: >-
    H2O.ai publishes security bulletins. The Trust Center also posts CVE responses — at
    capture time it carried a statement that H2O.ai had identified no externally exposed
    systems affected by CVE-2025-55182 (React / Next.js).
pgp_key: null
safe_harbor: not-published
evidence:
- {source: 'https://h2o.ai/security/', http_status: 200, fetched: '2026-08-04',
   quote: 'To report a possible security vulnerability, please submit here (/security/report-vulnerability)'}
- {source: 'https://h2o.ai/security/report-vulnerability', http_status: 200, fetched: '2026-08-04'}
- {source: 'https://trust.h2o.ai/', http_status: 200, fetched: '2026-08-04',
   note: 'lists security@h2o.ai for general security support and sesecurity@h2o.ai for responsible disclosure / vulnerability reports'}
gaps:
- No RFC 9116 /.well-known/security.txt on any host
- No published safe-harbor statement or disclosure timeline
- No bug bounty program