Executive brief
h3's serveStatic utility, used to serve static assets from web servers and CDNs, contains a path traversal vulnerability that allows attackers to bypass security checks and read arbitrary files. An attacker can craft requests with double-encoded paths (e.g., `%252e%252e`) that survive validation but are later decoded by backend systems (CDNs, S3, object storage), enabling unauthorized access to sensitive files outside the intended asset directory.
Technical details
The vulnerability stems from conflicting decode stages in h3's static file serving. When `serveStatic` processes a URL like `/%252e%252e/etc/passwd`, the H3Event constructor first decodes it to `/%2e%2e/etc/passwd` (preserving %25 sequences). A second redundant `decodeURI()` call in serveStatic does not further decode `%2e` (since encodeURI never encodes the dot character), leaving `%2e%2e` intact. The `resolveDotSegments()` function only checks for literal `.` characters and fast-returns without traversal protection. URL-based backends (CDNs, S3) then interpret `%2e%2e` as `..` per RFC 3986/URL Standard, enabling path traversal. Affected versions: h3 ≤ 1.15.8. Patched in 1.15.9. Only URL-based backends are vulnerable; filesystem-based backends are not affected.
Affected products
- h3js h3 ≤ 1.15.8
Timeline
- 2026-03-20: disclosed
- 2026-03-20: patched: Version 1.15.9 released