Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mp2g-9vg9-f4cg | h3 v1 has Request Smuggling (TE.TE) issue |
Mon, 13 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Request Smuggling (TE.TE) in h3 v1 | h3 v1 has Request Smuggling (TE.TE) issue |
| References |
|
Fri, 23 Jan 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
H3
H3 h3 |
|
| CPEs | cpe:2.3:a:h3:h3:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
H3
H3 h3 |
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
H3js
H3js h3 |
|
| Vendors & Products |
H3js
H3js h3 |
Fri, 16 Jan 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 15 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 Jan 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP Request Smuggling vulnerability. readRawBody is doing a strict case-sensitive check for the Transfer-Encoding header. It explicitly looks for "chunked", but per the RFC, this header should be case-insensitive. This vulnerability is fixed in 1.15.5. | |
| Title | Request Smuggling (TE.TE) in h3 v1 | |
| Weaknesses | CWE-444 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-13T16:48:19.873Z
Reserved: 2026-01-13T18:22:43.981Z
Link: CVE-2026-23527
Updated: 2026-01-15T19:59:59.151Z
Status : Modified
Published: 2026-01-15T20:16:05.620
Modified: 2026-04-13T17:16:27.900
Link: CVE-2026-23527
OpenCVE Enrichment
Updated: 2026-04-15T18:15:10Z
Github GHSA