Junglewise Threat Intelligence

CVE-2026-33128: h3 Server-Sent Events injection via unsanitized newlines

CVE-2026-33128 · Severity: low · CVSS 3.1 · Published 2026-03-18

Technologies: Uber H3-Js, H3js H3. Vendors: Uber.

Executive brief

h3 is a minimal HTTP framework used to build web services with Server-Sent Events (SSE) for real-time messaging. The framework fails to sanitize newline characters in SSE message fields (event, data, id, comment), allowing attackers who control any message field to inject arbitrary SSE events, forge privileged notifications, or trigger denial-of-service through reconnection manipulation. Applications using SSE for chat, notifications, or live dashboards are vulnerable to cross-user message injection and phishing attacks.

Technical details

The vulnerability is a CRLF injection (CWE-93) in the createEventStream functionality. The functions formatEventStreamMessage() and formatEventStreamComment() in src/utils/internal/event-stream.ts (lines 170–187) directly interpolate user-controlled strings into SSE wire format without removing newline characters (\n). Since the SSE protocol uses \n as a field delimiter and \n\n as an event separator, an attacker who controls any message field can inject arbitrary SSE directives (event:, data:, id:, retry:) or entirely new events. Attack vectors include network-accessible SSE endpoints in chat/notification applications, notification systems, and collaborative tools where user input flows into message fields. No authentication or user interaction is required—only the ability to influence a message field. Fixes are available in versions ≥1.15.6 (for v1.x) and ≥2.0.1-rc.15 (for v2.x).

Affected products

  • h3js h3 0 to 1.15.5; 2.0.0 to 2.0.1-rc.14

Timeline

  • 2026-03-18: disclosed: Advisory GHSA-22cc-p3c6-wpvm published
  • 2026-03-18: patched: Fixed in v1.15.6 and v2.0.1-rc.15

References

Related threats