CVE-2026-86250 | h3js h3 up to 2.0.1-rc.17 Cookie setChunkedCookie/deleteChunkedCookie infinite loop
A vulnerability described as problematic has been identified in h3js h3 up to 2.0.1-rc.17. This affects the function setChunkedCookie/deleteChunkedCookie of the component Cookie Handler. Executing a manipulation can lead to infinite loop.
This vulnerability appears as CVE-2026-86250. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More