CVE-2026-86250

Description

A flaw was found in h3. This vulnerability allows a remote attacker to send a specially crafted cookie header with an excessively large chunk count. This action triggers an inefficient cleanup process within the setChunkedCookie() and deleteChunkedCookie() functions, consuming significant server resources. Consequently, the server process can hang, leading to a denial of service (DoS) for legitimate users.

Statement

Important: A denial of service flaw in the h3 library, affecting Red Hat OpenShift AI, allows a remote unauthenticated attacker to send a specially crafted cookie header. This can trigger an inefficient cleanup loop, leading to resource exhaustion and rendering the server unresponsive.

Mitigation

To mitigate this issue, restrict network access to services utilizing the h3 component, such as odh-feature-server-rhel9 in Red Hat OpenShift AI, to trusted clients and networks only. Implement firewall rules to limit exposure of the affected service ports. This operational control reduces the attack surface by preventing untrusted external access. If the service is reloaded or restarted, ensure firewall rules persist.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.5N/A7.5
Attack VectorNetworkN/ANetwork
Attack ComplexityLowN/ALow
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityNoneN/ANone
Integrity ImpactNoneN/ANone
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU)

Frequently Asked Questions

Want to get errata notifications? Sign up here.