CVE-2026-86253

Summary

h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dot segments (%2e%2e) are passed to decodeURI() and decoded to ../ sequences without sanitization. An unauthenticated remote attacker can send crafted requests to endpoints served by serveStatic() to read arbitrary files outside the intended static directory. Fixed in 1.15.6 and 2.0.1-rc.15.

Affected Software

VendorProductVersion RangeStatus
h3jsh30 < 1.15.6affected
h3jsh31.15.6unaffected
h3jsh32.0.0-beta.0 < 2.0.1-rc.15affected
h3jsh32.0.1-rc.15unaffected

Weaknesses

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

References