Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 06 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
H3js
H3js h3 |
|
| Vendors & Products |
H3js
H3js h3 |
Sun, 06 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type directives, split single push calls into multiple browser-parsed events, or escape comment fields to inject data, bypassing the prior CVE fix that only addressed newline injection. | |
| Title | h3 before 1.15.9 SSE Event Injection via Carriage Return | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-06T12:00:27.561Z
Reserved: 2026-09-06T11:35:19.316Z
Link: CVE-2026-86252
No data.
Status : Received
Published: 2026-09-06T12:17:16.033
Modified: 2026-09-06T12:17:16.033
Link: CVE-2026-86252
No data.
OpenCVE Enrichment
Updated: 2026-09-06T14:00:07Z
-
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')