CVE-2026-86205CWE-601

CVE-2026-86205

Medium · published September 6, 2026

CVSS v3.1
5.4
EPSS
In the wild
Unconfirmed
What it is

h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers can craft a same-origin URL with a double-slash path segment that passes origin validation but produces a Location header interpreted by browsers as a protocol-relative redirect to an external domain.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS
Not scored
Weakness
CWE-601 · URL Redirection to Untrusted Site ('Open Redirect')
Published
2026-09-06T16:17Z
References (2)
Timeline
  • 06 SEP 12:00Z
    h3 before 2.0.1-rc.18 Open Redirect via redirectBack()
    cvelistv5