Executive brief
h3 is a minimal HTTP framework used to build web services and APIs. An attacker can bypass authentication and authorization middleware by crafting a malicious Host header, allowing them to access protected routes that should be restricted. This could enable unauthorized access to sensitive internal endpoints and functions.
Technical details
The vulnerability exists in h3's NodeRequestUrl class, which extends FastURL. When accessing event.url or event.url.hostname in middleware (e.g., during logging), the _url() getter is triggered, which reconstructs the URL from untrusted components including the Host header. An attacker can pollute the Host header with a path-like string (e.g., "localhost:3000/abchehe?") that causes the href property to be malformed. Since route handlers are resolved before middleware execution, but middleware path matching uses the spoofed event.url, an attacker can bypass middleware authentication checks by requesting a protected route with a crafted Host header. The vulnerability affects h3 versions 2.0.0-0 through 2.0.1-rc.14, and a fix is available in version 2.0.1-rc.15 or later. Network reachability is required; no authentication or user interaction is needed.
Affected products
- h3js h3 >=2.0.0-0, <2.0.1-rc.15
Timeline
- 2026-03-18: disclosed
- 2026-03-18: patched: Fixed in version 2.0.1-rc.15