5.3

CVE-2026-33490

Exploit

h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes

H3 is a minimal H(TTP) framework. In versions 2.0.0-0 through 2.0.1-rc.16, the `mount()` method in h3 uses a simple `startsWith()` check to determine whether incoming requests fall under a mounted sub-application's path prefix. Because this check does not verify a path segment boundary (i.e., that the next character after the base is `/` or end-of-string), middleware registered on a mount like `/admin` will also execute for unrelated routes such as `/admin-public`, `/administrator`, or `/adminstuff`. This allows an attacker to trigger context-setting middleware on paths it was never intended to cover, potentially polluting request context with unintended privilege flags. Version 2.0.2-rc.17 contains a patch.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
H3 ≫ H3 Version 2.0.1 Update rc1 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc10 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc11 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc12 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc13 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc14 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc15 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc16 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc2 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc3 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc4 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc5 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc6 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc7 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc8 SwPlatform node.js
H3 ≫ H3 Version 2.0.1 Update rc9 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.146
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
security-advisories@github.com 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-706 Use of Incorrectly-Resolved Name or Reference

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

https://github.com/h3js/h3/security/advisories/GHSA-2j6q-whv2-gh6w
Vendor Advisory
Exploit
Mitigation