Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-22cc-p3c6-wpvm | h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields |
Fri, 20 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
H3
H3 h3 |
|
| CPEs | cpe:2.3:a:h3:h3:*:*:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.0:*:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc10:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc11:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc12:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc13:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc14:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc2:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc3:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc4:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc5:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc6:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc7:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc8:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc9:*:*:*:node.js:*:* |
|
| Vendors & Products |
H3
H3 h3 |
Fri, 20 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
H3js
H3js h3 |
|
| Vendors & Products |
H3js
H3js h3 |
Fri, 20 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Mar 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent Events (SSE) injection due to missing newline sanitization in formatEventStreamMessage() and formatEventStreamComment(). An attacker who controls any part of an SSE message field (id, event, data, or comment) can inject arbitrary SSE events to connected clients. This issue is fixed in versions 1.15.6 and 2.0.1-rc.15. | |
| Title | h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-20T11:40:27.956Z
Reserved: 2026-03-17T20:35:49.927Z
Link: CVE-2026-33128
Updated: 2026-03-20T11:40:21.329Z
Status : Analyzed
Published: 2026-03-20T10:16:19.160
Modified: 2026-03-20T20:00:21.330
Link: CVE-2026-33128
No data.
OpenCVE Enrichment
Updated: 2026-03-25T14:29:40Z
Github GHSA