Bug 2529156 (CVE-2026-86253)
| Summary: | CVE-2026-86253 h3: h3: Arbitrary File Read via Path Traversal | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in h3, an npm package. An unauthenticated remote attacker can exploit this vulnerability by sending crafted requests to endpoints served by the `serveStatic()` function. On Node.js deployments, the `event.url.pathname` is not properly normalized, allowing percent-encoded dot segments to be decoded into directory traversal sequences without sanitization. This path traversal vulnerability enables the attacker to read arbitrary files outside the intended static directory, leading to information disclosure.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-06 12:11:33 UTC
|