Subscriptions
No data.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-22cc-p3c6-wpvm | h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 20 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Mar 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent Events (SSE) injection due to missing newline sanitization in formatEventStreamMessage() and formatEventStreamComment(). An attacker who controls any part of an SSE message field (id, event, data, or comment) can inject arbitrary SSE events to connected clients. This issue is fixed in versions 1.15.6 and 2.0.1-rc.15. | |
| Title | h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-20T11:40:27.956Z
Reserved: 2026-03-17T20:35:49.927Z
Link: CVE-2026-33128
Updated: 2026-03-20T11:40:21.329Z
Status : Awaiting Analysis
Published: 2026-03-20T10:16:19.160
Modified: 2026-03-20T13:37:50.737
Link: CVE-2026-33128
No data.
OpenCVE Enrichment
Updated: 2026-03-20T10:36:24Z
Github GHSA