
CVE-2026-33129 H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability in the requireBasicAuth function due to the use… https://www.cve.org/CVERecord?id=CVE-2026-33129
Post summary
A timing side‑channel flaw was identified in H3 framework's requireBasicAuth across certain versions; no exploitation or mitigation details are provided.

