H2 is not recommended for production and is used mainly as an embedded db for development or evaluation purposes. Magnolia normally keeps it in sync with the version used by JackRabbit.
Also, according to some vulnerability detection tools, Magnolia results affected by h2 1.4.x CVEs, even though it is actually not (see BUILD-609).
The latest major h2 version (2.1.x) introduces breaking changes when updating from the version currently bundled with Magnolia (1.4.x) which may disrupt work for devs.
Document this in release notes and mention how to workaround the issue. See https://jira.magnolia-cms.com/browse/MAGNOLIA-8638?focusedId=331710&page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel#comment-331710