← volver
CVE-2026-33128

h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields

CVSS 7.5 HIGHEPSS 0.5%CWE-93
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.5EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
20 mar 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent Events (SSE) injection due to missing newline sanitization in formatEventStreamMessage() and formatEventStreamComment(). An attacker who controls any part of an SSE message field (id, event, data, or comment) can inject arbitrary SSE events to connected clients. This issue is fixed in versions 1.15.6 and 2.0.1-rc.15.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
Productos afectados
h3js · h3

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →