10

CVE-2026-33128

Exploit

h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields

H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent Events (SSE) injection due to missing newline sanitization in formatEventStreamMessage() and formatEventStreamComment(). An attacker who controls any part of an SSE message field (id, event, data, or comment) can inject arbitrary SSE events to connected clients. This issue is fixed in versions 1.15.6 and 2.0.1-rc.15.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
H3 ≫ H3 SwPlatform node.js Version < 1.15.6
H3 ≫ H3 Version 2.0.0 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc10 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc11 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc12 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc13 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc14 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc2 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc3 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc4 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc5 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc6 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc7 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc8 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc9 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.433
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
security-advisories@github.com 7.5 2.2 4.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

https://github.com/h3js/h3/security/advisories/GHSA-22cc-p3c6-wpvm
Vendor Advisory
Exploit
https://github.com/h3js/h3/commit/7791538e15ca22437307c06b78fa155bb73632a6
Patch
https://github.com/h3js/h3/blob/52c82e18bb643d124b8b9ec3b1f62b081f044611/src/utils/internal/event-stream.ts#L170-L187
Product