Junglewise Threat Intelligence

CVE-2026-23527: h3js h3 HTTP request smuggling in readRawBody

CVE-2026-23527 · Severity: high · CVSS 8.9 · Published 2026-01-15

Technologies: Uber H3-Js, h3 (npm). Vendors: Uber, npm.

Executive brief

A vulnerability in the h3 web framework could allow attackers to bypass security filters or interfere with other users' web traffic. By sending specially crafted web requests with unusual capitalization, an attacker can trick the server into misinterpreting where one request ends and the next begins. This can lead to unauthorized access to data or the ability to hijack sessions when the application is hosted behind certain types of load balancers.

Technical details

The h3 library (v1.15.4 and earlier) fails to perform case-insensitive validation of the 'Transfer-Encoding' HTTP header in its 'readRawBody' function. While the HTTP specification requires this header to be case-insensitive, h3 specifically looks for the lowercase string 'chunked'. If an attacker provides a mixed-case header like 'Transfer-Encoding: ChuNked', h3 fails to recognize the chunked body and assumes a content length of zero. This leads to a TE.TE desynchronization vulnerability when h3 is deployed behind intermediaries (like AWS NLB or certain Node.js proxies) that do not normalize header casing, allowing an attacker to smuggle a second request within the body of the first. This can be used to bypass WAFs or poison the socket for subsequent users. The issue is fixed in version 1.15.5 by normalizing header values to lowercase before validation.

Affected products

  • h3js h3 <= 1.15.4

Timeline

  • 2026-01-15: disclosed
  • 2026-01-15: advisory
  • 2026-01-15: patched: Fixed in v1.15.5

References

Related threats