CVE-2026-86253
MediumAdvisory
Published 18 Mar 2026In the index since 10 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.9
- base score, highest
- EPSS
- 0.004
- 36th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 8
- of 17,781 indexed, latest versions
- Container images
- 7
- deployed by those charts
- Fix available
- 1 of 1
- affected package
h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read
Carried by container images the latest versions of 8 of 17,781 indexed charts deploy, on 7 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| h3npm | 1.8.2, 1.10.0, 1.10.2, 1.12.0+2 more | 1.15.6 | 7 |
- OSV records
- GHSA-wr4h-v87w-p3r7
Charts affected
8 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| homarroben01Verified publisher | 1.4.0 | 1 of 1See more | 2,581 |
| astrotrekastria | 0.0.2 | 1 of 4See more | 32,501 |
| tianjimsgbyte | 0.1.17 | 1 of 2See more | 4,560 |
| wireguardnicklasfrahm-wireguard | 0.2.0 | 1 of 1See more | 1,157 |
| wg-easyrm3lVerified publisher | 0.2.0 | 1 of 1See more | 1,157 |
| speckle-server-branch-testing5speckleVerified publisher | 2.21.3-branch.testing5.219631-2153bef | 1 of 5See more | 15,635 |
| homarrvhdirkVerified publisher | 0.1.5 | 1 of 1See more | 2,789 |
| sirenwateim | 1.0.2 | 1 of 1See more | 5,984 |
Container images carrying it
7 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 5f26407fd2ed | h3 | 1.15.6 | 2 |
| moonrailgun/ | b528c8f8fcc4 | h3 | 1.15.6 | 1 |
| sigp/ | 2c219b04758e | h3 | 1.15.6 | 1 |
| speckle/ | d4ca6ebf09b9 | h3 | 1.15.6 | 1 |
| ghcr.io/ | 737ec361ed24 | h3 | 1.15.6 | 1 |
| ghcr.io/ | e103abadfb52 | h3 | 1.15.6 | 1 |
| ghcr.io/ | 5889bea38e56 | h3 | 1.15.6 | 1 |