Denial of Service Vulnerability in h3 Framework by h3js
CVE-2026-86250

8.7HIGH

Key Information:

Vendor

H3js

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-86250?

The h3 framework, specifically versions prior to 2.0.1-rc.18, contains a vulnerability where it fails to properly validate chunk counts derived from user-controlled cookie values. This weakness can be exploited by attackers who send specially crafted cookie headers with abnormally high chunk counts, leading to an O(n²) cleanup loop. This loop can overwhelm server processes, resulting in denial of service. Addressing this issue is crucial for maintaining server availability and performance.

Affected Version(s)

h3 2.0.0-beta.4 < 2.0.1-rc.18

h3 2.0.1-rc.18

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.