Executive brief
h3 is a lightweight HTTP framework used to build web services and APIs. The framework's basic authentication function uses an unsafe string comparison that leaks timing information, allowing attackers to guess valid passwords one character at a time by measuring response times. This is particularly effective in cloud or local network environments, converting password cracking from an exponential problem to a linear one.
Technical details
A timing side-channel vulnerability exists in h3's requireBasicAuth function due to use of the standard !== operator for password comparison. The vulnerable code performs direct string comparison: if (opts.password && password !== opts.password). In V8 and most JavaScript runtimes, !== is optimized to "fail fast"—it stops and returns false as soon as the first mismatched byte is encountered, causing varying execution times based on where the first character mismatch occurs. An attacker can statistically measure these timing differences over multiple requests to deduce the correct password one character at a time, reducing complexity from exponential (guessing the entire string) to linear (guessing one character per attempt). This is feasible remotely in low-latency environments (co-located cloud instances, local networks) and highly effective despite network jitter. The fix (available in v2.0.1-rc.9 and later) implements constant-time string comparison and timing jitter to prevent this disclosure. Affected versions: h3 v2.0.0-beta.0 through v2.0.0-rc.8.
Affected products
- h3js h3 >=v2.0.0-beta.0, <=v2.0.0-rc.8
Timeline
- 2026-03-18: disclosed: GHSA-26f5-8h2x-34xh published
- 2026-01-19: patched: Patch released in v2.0.1-rc.9 with constant-time comparison and timing jitter