CVE-2026-86253

h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dot segments (%2e%2e) are passed to decodeURI() and decoded to ../ sequences without sanitization. An unauthenticated remote attacker can send crafted requests to endpoints served by serveStatic() to read arbitrary files outside the intended static directory. Fixed in 1.15.6 and 2.0.1-rc.15.

  • Published Sep 6, 2026
  • CVSS 8.2 high
  • 0.6% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-86253 at the National Vulnerability Database