Vulnerabilities in h3js
11 resultsVexday analysis
O h3js apresenta 6 vulnerabilidades catalogadas sem casos de exploração ativa registrada. Nenhuma vulnerabilidade crítica foi identificada e não há publicações recentes, indicando um risco contido. A fraqueza predominante está em deficiências gerais de controle de criptografia (CWE-706), sugerindo exposição a problemas de codificação cryptográfica que devem ser monitorados durante atualizações.
CVE-2026-23527HIGHh3 v1 has Request Smuggling (TE.TE) issueEPSS 0.6%CVE-2026-33128HIGHh3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream FieldsEPSS 0.6%CVE-2026-86253HIGHh3 before 1.15.6 Path Traversal via Percent-Encoded Dot SegmentsEPSS 0.4%CVE-2026-33131HIGHh3 has a middleware bypass with one gadgetEPSS 0.4%CVE-2026-33129MEDIUMh3 has an observable timing discrepancy in basic auth utilsEPSS 0.3%CVE-2026-86251HIGHh3 before 1.15.9 Path Traversal via Double DecodingEPSS 0.3%CVE-2026-86250HIGHh3 before 2.0.1-rc.18 Denial of Service via Unbounded Chunked CookieEPSS 0.3%CVE-2026-33732MEDIUMsrvx is vulnerable to middleware bypass via absolute URI in request lineEPSS 0.2%CVE-2026-33490LOWh3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching RoutesEPSS 0.2%CVE-2026-86252MEDIUMh3 before 1.15.9 SSE Event Injection via Carriage ReturnEPSS 0.2%CVE-2026-86205MEDIUMh3 before 2.0.1-rc.18 Open Redirect via redirectBack()EPSS 0.2%