CVE-2026-33131General(h3 / h3)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which extends FastURL) which allows middleware bypass. When event.url, event.url.hostname, or event.url._url is accessed, such as in a logging middleware, the _url getter constructs a URL from untrusted data, including the user-controlled Host header. Because H3's router resolves the route handler before middleware runs, an attacker can supply a crafted Host header (e.g., Host: localhost:3000/abchehe?) to make the middleware path check fail while the route handler still matches, effectively bypassing authentication or authorization middleware. This affects any application built on H3 (including Nitro/Nuxt) that accesses event.url properties in middleware guarding sensitive routes. The issue requires an immediate fix to prevent FastURL.href from being constructed with unsanitized, attacker-controlled input. Version 2.0.1-rc.15 contains a patch for this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • h3

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
h3

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-22: 1Mentions · 2026-03-23: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 103-2003-2203-23
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-201
General1
2026-03-221
Disclosure1
2026-03-231
General1
Full discourse3 posts
  • IntegSec@integ_sec
    General

    CVE-2026-33131: H3 Framework Middleware Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q047VD_F0

    Post summary

    The fragment offers only a headline and a link, lacking any concrete details about the vulnerability, exploitation, or remediation.

    0000034
    30 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33131 H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which extends FastURL) whic… https://www.cve.org/CVERecord?id=CVE-2026-33131

    Post summary

    The text discloses a host‑header spoofing flaw in the H3 HTTP framework for specific versions, but provides no proof‑of‑concept, exploit code, active exploitation evidence, or patch information.

    00000100
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33131 H3 Framework Host Header Injection Vulnerability in Middleware Bypass https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33131

    Post summary

    The post references a new CVE for a Host Header Injection vulnerability in the H3 Framework and links to a vulnerability database, but provides no additional technical, exploit, or mitigation details.

    0000043
    4.0K followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Apph3h32.0.0node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-
Apph3h32.0.1node.js-

Explore more