CPE
The h3 library is vulnerable to a denial of service attack due to improper input validation of cookie chunk counts, allowing an attacker to trigger an O(n²) cleanup loop that hangs the server process.