Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-26f5-8h2x-34xh | h3 has an observable timing discrepancy in basic auth utils |
Fri, 20 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
H3
H3 h3 |
|
| CPEs | cpe:2.3:a:h3:h3:2.0.0:*:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc1:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc2:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc3:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc4:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc5:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc6:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc7:*:*:*:node.js:*:* cpe:2.3:a:h3:h3:2.0.1:rc8:*:*:*:node.js:*:* |
|
| Vendors & Products |
H3
H3 h3 |
Fri, 20 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
H3js
H3js h3 |
|
| Vendors & Products |
H3js
H3js h3 |
Fri, 20 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability in the requireBasicAuth function due to the use of unsafe string comparison (!==). This allows an attacker to deduce the valid password character-by-character by measuring the server's response time, effectively bypassing password complexity protections. This issue is fixed in version 2.0.1-rc.9. | |
| Title | h3 has an observable timing discrepancy in basic auth utils | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-20T19:33:49.871Z
Reserved: 2026-03-17T20:35:49.927Z
Link: CVE-2026-33129
Updated: 2026-03-20T19:33:40.303Z
Status : Analyzed
Published: 2026-03-20T10:16:19.317
Modified: 2026-03-20T19:58:02.500
Link: CVE-2026-33129
No data.
OpenCVE Enrichment
Updated: 2026-03-25T14:29:39Z
Github GHSA