h3js
- Total products in the ecosystem
- 2
- Total vulnerabilities (90 days)
- 5
en
Verify to analyze this security profile
As of 09/19/2026, h3js recorded 5 security vulnerabilities in the last 90 days across 1 products, including 3 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, h3 had the most security vulnerabilities in the h3js ecosystem, with 5 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-86253h3 before 1.15.6 Path Traversal via Percent-Encoded Dot Segments | Exploitation statusNot known exploited | FixYes | Affected producth3 | Published09/06/2026 | SeverityHigh |
CVE-2026-86252h3 before 1.15.9 SSE Event Injection via Carriage Return | Exploitation statusPublic exploit | FixYes | Affected producth3 | Published09/06/2026 | SeverityMedium |
CVE-2026-86251h3 before 1.15.9 Path Traversal via Double Decoding | Exploitation statusPublic exploit | FixYes | Affected producth3 | Published09/06/2026 | SeverityHigh |
CVE-2026-86250h3 before 2.0.1-rc.18 Denial of Service via Unbounded Chunked Cookie | Exploitation statusNot known exploited | FixYes | Affected producth3 | Published09/06/2026 | SeverityHigh |
CVE-2026-86205h3 before 2.0.1-rc.18 Open Redirect via redirectBack() | Exploitation statusPublic exploit | FixYes | Affected producth3 | Published09/06/2026 | SeverityMedium |
CVE-2026-33732srvx is vulnerable to middleware bypass via absolute URI in request line | Exploitation statusNot known exploited | FixNot confirmed | Affected productsrvx | Published03/26/2026 | SeverityMedium |
CVE-2026-33490h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes | Exploitation statusPublic exploit | FixNot confirmed | Affected producth3 | Published03/26/2026 | SeverityLow |
CVE-2026-33131h3 has a middleware bypass with one gadget | Exploitation statusPublic exploit | FixNot confirmed | Affected producth3 | Published03/20/2026 | SeverityHigh |
CVE-2026-33129h3 has an observable timing discrepancy in basic auth utils | Exploitation statusPublic exploit | FixYes | Affected producth3 | Published03/20/2026 | SeverityMedium |
CVE-2026-33128h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields | Exploitation statusPublic exploit | FixYes | Affected producth3 | Published03/20/2026 | SeverityHigh |
CVE-2026-23527h3 v1 has Request Smuggling (TE.TE) issue | Exploitation statusNot known exploited | FixYes | Affected producth3 | Published01/15/2026 | SeverityHigh |