h3js h3

5 known vulnerabilities in h3js h3, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-86253 CVSS 8.2 high h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments…
  • CVE-2026-86252 CVSS 6.9 medium h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject…
  • CVE-2026-86251 CVSS 8.2 high h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path…
  • CVE-2026-86250 CVSS 8.7 high h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and…
  • CVE-2026-86205 CVSS 5.3 medium h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize…