← Back

CVE-2026-33128

nvd nist
Published: Mar 20, 2026Modified: Jun 17, 2026

JSON object

Loading...
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: NVD

Description

H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent Events (SSE) injection due to missing newline sanitization in formatEventStreamMessage() and formatEventStreamComment(). An attacker who controls any part of an SSE message field (id, event, data, or comment) can inject arbitrary SSE events to connected clients. This issue is fixed in versions 1.15.6 and 2.0.1-rc.15.

Affected (15)

Products: H3: H3
1 product
H3
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
H3
Before 1.15.6
Version 2.0.0
Version 2.0.1 rc10
Version 2.0.1 rc11
Version 2.0.1 rc12
Version 2.0.1 rc13
Version 2.0.1 rc14
Version 2.0.1 rc2
Version 2.0.1 rc3
Version 2.0.1 rc4
Version 2.0.1 rc5
Version 2.0.1 rc6
Version 2.0.1 rc7
Version 2.0.1 rc8
Version 2.0.1 rc9

Timeline

No history available yet.