Path Traversal Vulnerability in h3 Server Utility
CVE-2026-86251
8.2HIGH
What is CVE-2026-86251?
The h3 server utility versions prior to 1.15.9 contain a path traversal vulnerability due to a double-decoding issue. An attacker can exploit this flaw by crafting a request path with double-encoded dot sequences, which could be decoded improperly, allowing for unauthorized access to files on the backend. This risk arises when URLs are processed by URL-based backends like CDNs or object storage solutions, potentially leading to exposure of sensitive data. It is crucial for users to upgrade to the latest version to safeguard against this vulnerability.
Affected Version(s)
h3 0 < 1.15.9
h3 1.15.9
