VYPR

H3

by RubyGems

CVEs (2)

  • CVE-2026-86252Sep 6, 2026
    risk 0.00cvss epss

    h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type directives, split single push calls into…

  • CVE-2026-86251Sep 6, 2026
    risk 0.00cvss epss

    h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequences (e.g. %252e%252e) to be decoded to %2e%2e, which survives resolveDotSegments() because that function…