H3's vulnerability footprint spans a small, focused set of products centered on the H3 and SRVX networking and protocol-handling components, which despite narrow product scope carry disproportionate risk due to their foundational role in HTTP/3 and related critical infrastructure. The vendor's disclosures skew strongly toward critical-severity outcomes and recur through weakness classes including name-resolution flaws, authentication bypass through spoofing, CRLF injection, HTTP request smuggling, and timing-based side channels—a pattern reflecting the complexity and trust-boundary sensitivity inherent in protocol parsing and cryptographic verification. Defenders should monitor this vendor's advisories closely and prioritize remediation of affected protocol-facing components; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by H3 over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-23527CRITICAL H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP Request Smuggling vulnerability. readRawBody is doing a stric | Jan 15, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-33128CRITICAL H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent Events (SSE) injection due to mi | Mar 20, 2026 | 10.0 | 32 | NO | NO |
CVE-2026-33131CRITICAL H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which extends FastURL) which allows middl | Mar 20, 2026 | 9.1 | 29 | NO | NO |
CVE-2026-33732MEDIUM srvx is a universal server based on web standards. Prior to version 0.11.13, a pathname parsing discrepancy in srvx's `FastURL` allows middleware bypass on the Node.js adapter when | Mar 26, 2026 | 6.5 | 23 | NO | NO |
CVE-2026-33129MEDIUM H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability in the requireBasicAuth function due to the use of unsafe str | Mar 20, 2026 | 5.9 | 21 | NO | NO |
CVE-2026-33490MEDIUM H3 is a minimal H(TTP) framework. In versions 2.0.0-0 through 2.0.1-rc.16, the `mount()` method in h3 uses a simple `startsWith()` check to determine whether incoming requests fall | Mar 26, 2026 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by H3.
Media articles that mention a CVE ID that affects a product developed by H3 — matched by CVE ID, not by vendor name.