CVE-2026-86205: Schwachstellen-Eintrag (NVD)
h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers can craft a same-origin URL with a double-slash path segment that passes origin validation but produces a Location header interpreted by browsers as a protocol-relative redirect to an external domain.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-06 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-86205 | h3js h3 up to 2.0.1-rc.17 Redirect Utility redirectBack (EUVD-2026-72105)
A vulnerability marked as problematic has been reported in h3js h3 up to 2.0.1-rc.17. The impacted element is the function redirectBack of the component Redirect Utility. Performing a manipulation results in open redirect. This vulnerabilit