h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields
Modified: 3/20/2026
package
pkg:npm/h3
h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields
Modified: 3/20/2026
h3 has an observable timing discrepancy in basic auth utils
Modified: 3/20/2026
h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes
Modified: 3/27/2026
h3 has a middleware bypass with one gadget
Modified: 3/20/2026
h3: SSE Event Injection via Unsanitized Carriage Return (`\r`) in EventStream Data and Comment Fields (Bypass of CVE Fix)
Modified: 9/10/2026
h3: Double Decoding in `serveStatic` Bypasses `resolveDotSegments` Path Traversal Protection via `%252e%252e`
Modified: 9/10/2026
H3 has an Open Redirect via Protocol-Relative Path in redirectBack() Referer Validation
Modified: 9/10/2026
h3 v1 has Request Smuggling (TE.TE) issue
Modified: 4/13/2026
H3: Unbounded Chunked Cookie Count in Session Cleanup Loop may Lead to Denial of Service
Modified: 9/10/2026
h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read
Modified: 9/10/2026