THREAT OPS › Threat News › [NVD] CVE-2026-86252 (MEDIUM 5.3) — h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type directives, split single push calls into mult
[NVD] CVE-2026-86252 (MEDIUM 5.3) — h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type directives, split single push calls into mult
CVE-2026-86252 CVSS: 5.3 MEDIUM Published: 2026-09-06T12:17:16.033
h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type directives, split single push calls into multiple browser-parsed events, or escape comment fields
Indicators of compromise
- CVE-2026-86252cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86252