h3
h3js- Product type
- Other
- Catalog vulnerabilities
- 10
Severity across 10 analyzed records
Verify to analyze this security profile
en
As of 09/19/2026, within CyStack's analyzed data, h3 has 5 security vulnerabilities published in the last 90 days. Of these, 3 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of h3 and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-86253h3 before 1.15.6 Path Traversal via Percent-Encoded Dot Segments | Exploitation statusNot known exploited | FixYes | Published09/06/2026 | SeverityHigh |
CVE-2026-86252h3 before 1.15.9 SSE Event Injection via Carriage Return | Exploitation statusPublic exploit | FixYes | Published09/06/2026 | SeverityMedium |
CVE-2026-86251h3 before 1.15.9 Path Traversal via Double Decoding | Exploitation statusPublic exploit | FixYes | Published09/06/2026 | SeverityHigh |
CVE-2026-86250h3 before 2.0.1-rc.18 Denial of Service via Unbounded Chunked Cookie | Exploitation statusNot known exploited | FixYes | Published09/06/2026 | SeverityHigh |
CVE-2026-86205h3 before 2.0.1-rc.18 Open Redirect via redirectBack() | Exploitation statusPublic exploit | FixYes | Published09/06/2026 | SeverityMedium |
CVE-2026-33490h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes | Exploitation statusPublic exploit | FixNot confirmed | Published03/26/2026 | SeverityLow |
CVE-2026-33131h3 has a middleware bypass with one gadget | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2026 | SeverityHigh |
CVE-2026-33129h3 has an observable timing discrepancy in basic auth utils | Exploitation statusPublic exploit | FixYes | Published03/20/2026 | SeverityMedium |
CVE-2026-33128h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields | Exploitation statusPublic exploit | FixYes | Published03/20/2026 | SeverityHigh |
CVE-2026-23527h3 v1 has Request Smuggling (TE.TE) issue | Exploitation statusNot known exploited | FixYes | Published01/15/2026 | SeverityHigh |