H3 在 2.0.1-rc.18 之前的版本中,其 工具函数存在一个开放重定向漏洞。该漏洞的原因是未能对 Referer 头中的协议相对路径(protocol-relative paths)进行过滤处理。攻击者可以构造一个同源 URL,其中包含双斜杠路径段(如 )。这个路径段能够通过与原始 Referer 相同的协议和域名而通过源校验,但生成的 头会被浏览器解析为指向外部域名的协议相对重定向。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86250 | 7.5 HIGH | h3 before 2.0.1-rc.18 Denial of Service via Unbounded Chunked Cookie |
| CVE-2026-86251 | 5.9 MEDIUM | h3 before 1.15.9 Path Traversal via Double Decoding |
| CVE-2026-86253 | 5.9 MEDIUM | h3 before 1.15.6 Path Traversal via Percent-Encoded Dot Segments |
| CVE-2026-86252 | 5.3 MEDIUM | h3 before 1.15.9 SSE Event Injection via Carriage Return |
No comments yet