H3 在 1.15.9 之前的版本未能对 EventStream 数据字段和注释字段中的回车符(CR, \r)进行清理(sanitization),这使得攻击者可以通过包含未清理的回车符来注入任意 SSE(服务器发送事件)事件。攻击者可以利用这一点来注入事件类型指令、将单次 push 调用拆分为多个浏览器解析的事件,或从注释字段中逃逸以注入数据,从而绕过此前仅针对换行符(\n)注入问题的 CVE 修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86250 | 7.5 HIGH | h3 before 2.0.1-rc.18 Denial of Service via Unbounded Chunked Cookie |
| CVE-2026-86251 | 5.9 MEDIUM | h3 before 1.15.9 Path Traversal via Double Decoding |
| CVE-2026-86253 | 5.9 MEDIUM | h3 before 1.15.6 Path Traversal via Percent-Encoded Dot Segments |
| CVE-2026-86205 | 5.4 MEDIUM | h3 before 2.0.1-rc.18 Open Redirect via redirectBack() |
No comments yet