CVE-2026-33128General(h3 / h3)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent Events (SSE) injection due to missing newline sanitization in formatEventStreamMessage() and formatEventStreamComment(). An attacker who controls any part of an SSE message field (id, event, data, or comment) can inject arbitrary SSE events to connected clients. This issue is fixed in versions 1.15.6 and 2.0.1-rc.15.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • h3

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
h3

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-22: 1Technical Details · 2026-03-22: 103-2003-22
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-202
General2
2026-03-221
Disclosure1
Full discourse3 posts
  • isabel roses@isabelrosesss
    General

    beautiful women named CVE-2026-33128 messaging me

    Post summary

    The text merely references a CVE number in an unrelated, nonsensical phrase, providing no actionable or technical information.

    000232524
    508 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33128 H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent Events (SSE) injec… https://www.cve.org/CVERecord?id=CVE-2026-33128

    Post summary

    The message discloses technical details of CVE‑2026‑33128, outlining affected versions and the Server‑Sent Events injection vulnerability, but does not mention exploitation, patches, or a PoC.

    00000103
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33128 Server-Sent Events Injection Vulnerability in H3 HTTP Fra... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33128 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A short tweet references CVE-2026-33128 and links to a Vulmon details page, but offers no additional technical, exploitation, or mitigation information.

    0000041
    4.0K followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
Apph3h3-node.js-
Apph3h32.0.0node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-

Explore more