CVE-2026-86253: h3js h3
Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.
h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dot segments (%2e%2e) are passed to decodeURI() and decoded to ../ sequences without sanitization. An unauthenticated remote attacker can send crafted requests to endpoints served by serveStatic() to read arbitrary files outside the intended static directory. Fixed in 1.15.6 and 2.0.1-rc.15.
Affected products
- h3js h3: before 1.15.6 (fixed in 1.15.6); from 2.0.0-beta.0, before 2.0.1-rc.15 (fixed in 2.0.1-rc.15)
Published 2026-09-06. Last modified 2026-09-10.