Path Traversal Vulnerability in h3 Server Utility
CVE-2026-86251

8.2HIGH

Key Information:

Vendor

H3js

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-86251?

The h3 server utility versions prior to 1.15.9 contain a path traversal vulnerability due to a double-decoding issue. An attacker can exploit this flaw by crafting a request path with double-encoded dot sequences, which could be decoded improperly, allowing for unauthorized access to files on the backend. This risk arises when URLs are processed by URL-based backends like CDNs or object storage solutions, potentially leading to exposure of sensitive data. It is crucial for users to upgrade to the latest version to safeguard against this vulnerability.

Affected Version(s)

h3 0 < 1.15.9

h3 1.15.9

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.