Denial of Service Vulnerability in h3 Framework by h3js
CVE-2026-86250
8.7HIGH
What is CVE-2026-86250?
The h3 framework, specifically versions prior to 2.0.1-rc.18, contains a vulnerability where it fails to properly validate chunk counts derived from user-controlled cookie values. This weakness can be exploited by attackers who send specially crafted cookie headers with abnormally high chunk counts, leading to an O(n²) cleanup loop. This loop can overwhelm server processes, resulting in denial of service. Addressing this issue is crucial for maintaining server availability and performance.
Affected Version(s)
h3 2.0.0-beta.4 < 2.0.1-rc.18
h3 2.0.1-rc.18
