h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type directives, split single push calls into multiple browser-parsed events, or escape comment fields to inject data, bypassing the prior CVE fix that only addressed newline injection.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 06 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
H3js
H3js h3 |
|
| Vendors & Products |
H3js
H3js h3 |
Sun, 06 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type directives, split single push calls into multiple browser-parsed events, or escape comment fields to inject data, bypassing the prior CVE fix that only addressed newline injection. | |
| Title | h3 before 1.15.9 SSE Event Injection via Carriage Return | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-06T12:00:27.561Z
Updated: 2026-09-08T15:13:40.142Z
Reserved: 2026-09-06T11:35:19.316Z
Link: CVE-2026-86252
Updated: 2026-09-08T15:12:19.288Z
Status : Awaiting Analysis
Published: 2026-09-06T12:17:16.033
Modified: 2026-09-08T20:00:18.870
Link: CVE-2026-86252
No data.