CVE intelligence

CVE-2026-86252

h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject a

Published 2026-09-06 · CVSS

medium

NIST record