CVE intelligence

CVE-2026-86253

h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname

Published 2026-09-06 · CVSS

high

NIST record