MEDIUM 5.3 NVD
CVE-2026-86205
h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Refere
h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers can craft a same-origin URL with a double-slash path segment that passes origin validation but produces a Location header interpreted by browsers as a protocol-relative redirect to an external domain.
References
- https://github.com/h3js/h3/security/advisories/GHSA-fp4x-ggrf-wmc6
- https://www.vulncheck.com/advisories/h3-before-2.0.1-rc.18-open-redirect-via-redirectback
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-06 via NVD.
vulnfeed aggregates 10006 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.