在 2.0.1-rc.18 之前版本的 h3 中, 和 函数未正确校验从用户可控的 Cookie 值中解析出的分块数量(chunk count)。攻击者可发送一个精心构造的 Cookie 头,其中包含一个极大的分块数量,从而触发 O(n²) 的清理循环,导致服务器进程挂起。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86251 | 5.9 MEDIUM | h3 before 1.15.9 Path Traversal via Double Decoding |
| CVE-2026-86253 | 5.9 MEDIUM | h3 before 1.15.6 Path Traversal via Percent-Encoded Dot Segments |
| CVE-2026-86205 | 5.4 MEDIUM | h3 before 2.0.1-rc.18 Open Redirect via redirectBack() |
| CVE-2026-86252 | 5.3 MEDIUM | h3 before 1.15.9 SSE Event Injection via Carriage Return |
No comments yet