CVE-2026-86251 | h3js h3 up to 1.15.8 serveStatic utility resolveDotSegments path traversal
A vulnerability classified as problematic has been found in h3js h3 up to 1.15.8. This impacts the function resolveDotSegments of the component serveStatic utility. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-86251. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More