CVE-2026-86252: h3 before 1.15.9 SSE Event Injection via Carriage Return
Published Sep 6, 2026
·Updated
h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type directives, split single push calls into multiple browser-parsed events, or escape comment fields to inject data, bypassing the prior CVE fix that only addressed newline injection.
Affected Software
1 affected component
h3<1.15.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
h3to a version that resolves this vulnerability.Fixed in 1.15.9
Event History
Sep 6, 2026
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Sep 18, 58651
Event
via NVD·02:20 AM
Frequently Asked Questions
1
What release should teams upgrade to?
Upgrade h3 to version 1.15.9 or later. Versions before 1.15.9 are affected.