CVE-2026-86253 | h3js h3 up to 1.15.5/2.0.1-rc.14 Static File Serving serveStatic path traversal
A vulnerability was found in h3js h3 up to 1.15.5/2.0.1-rc.14. It has been classified as problematic. Affected by this issue is the function serveStatic of the component Static File Serving. Performing a manipulation results in path traversal.
This vulnerability is identified as CVE-2026-86253. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More