Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/h3 — 5 CVEs · VulnScope
pkg:npm/
h3
5 total CVEs
HIGH
3
MEDIUM
1
LOW
1
✅ Check your installed version
Check
All known vulnerabilities
HIGH
8.9
CVE-2026-23527
h3 v1 has Request Smuggling (TE.TE) issue
from 0, < 1.15.5
HIGH
7.5
CVE-2026-33128
h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields
>= 2.0.0, < 2.0.1-rc.15
HIGH
7.4
CVE-2026-33131
h3 has a middleware bypass with one gadget
>= 2.0.0-0, < 2.0.1-rc.15
MEDIUM
5.9
h3 has an observable timing discrepancy in basic auth utils
>= 2.0.0-beta.0, < 2.0.1-rc.9
LOW
3.7
h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes
>= 2.0.1-alpha.0, < 2.0.1-rc.17
CVE-2026-33129
CVE-2026-33490