CVE-2026-33128 is a critical Server-Sent Events (SSE) injection vulnerability affecting the H3 framework, specifically versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14. This flaw, caused by missing newline sanitization, allows an unauthenticated attacker to inject arbitrary SSE events to connected clients over the network with low complexity. Rated 10.0 CVSS (CRITICAL), it poses a high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and it is not on CISA's KEV catalog, organizations using affected H3 versions should apply patches 1.15.6 or 2.0.1-rc.15 immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.15.6CPE matchmatch criteria | cpe:2.3:a:h3:h3:*:*:*:*:*:node.js:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:h3:h3:2.0.0:*:*:*:*:node.js:*:* | ||
2.0.1CPE matchmatch criteria | cpe:2.3:a:h3:h3:2.0.1:rc10:*:*:*:node.js:*:* | ||
2.0.1CPE matchmatch criteria | cpe:2.3:a:h3:h3:2.0.1:rc11:*:*:*:node.js:*:* | ||
2.0.1CPE matchmatch criteria | cpe:2.3:a:h3:h3:2.0.1:rc12:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.