๐Ÿ” CVE Alert

CVE-2026-86205

MEDIUM 5.4

h3 before 2.0.1-rc.18 Open Redirect via redirectBack()

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers can craft a same-origin URL with a double-slash path segment that passes origin validation but produces a Location header interpreted by browsers as a protocol-relative redirect to an external domain.

CWE CWE-601
Vendor h3js
Product h3
Published Sep 6, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for h3js h3

Be the first to know when new medium vulnerabilities affecting h3js h3 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

h3js / h3
2.0.1-rc.17 < 2.0.1-rc.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/h3js/h3/security/advisories/GHSA-fp4x-ggrf-wmc6 vulncheck.com: https://www.vulncheck.com/advisories/h3-before-2.0.1-rc.18-open-redirect-via-redirectback

Credits

๐Ÿ” offset