Junglewise Threat Intelligence

CVE-2026-86253: h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname

CVE-2026-86253 · Severity: medium · CVSS 5.9 · Published 2026-09-06

Technologies: H3.

Executive brief

h3 is a popular Node.js HTTP framework that includes a static file serving utility. An unauthenticated attacker can exploit improper URL decoding to read arbitrary files on the server, including sensitive configuration files, environment variables, source code, and system files. The vulnerability bypasses security boundaries that are supposed to restrict file access to a designated directory.

Technical details

The vulnerability is a path traversal (CWE-22) in the serveStatic() function's handling of URL paths. The root cause is in src/utils/static.ts line 86, where h3 uses FastURL (from srvx) to parse request URLs. FastURL extracts the pathname via raw string slicing without normalizing dot segments or decoding percent-encoded characters. When a request arrives with %2e%2e (percent-encoded dot-dot), FastURL leaves it verbatim in event.url.pathname. The code then calls decodeURI() on this raw path, converting %2e to a literal dot, producing traversal sequences like /../. These unsanitized paths are passed directly to user callbacks (getMeta, getContents) without validation, allowing them to escape the static root directory when performing filesystem operations. The vulnerability affects h3 v2.x and earlier on Node.js; it does not affect runtimes with pre-parsed URL objects. Patches are available in versions ≥1.15.6 and ≥2.0.1-rc.15.

Affected products

  • h3 h3 <1.15.6, 2.0.0 to 2.0.1-rc.14

Timeline

  • 2026-03-18: disclosed
  • 2026-03-18: patched: Patches released in v1.15.6 and v2.0.1-rc.15

References