Host Header Spoofing Vulnerability in H3 Framework by H3
CVE-2026-33131

7.4HIGH

Key Information:

Vendor

H3js

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-33131?

The H3 framework, which serves as a minimal H(TTP) framework, contains a vulnerability that allows for host header spoofing between versions 2.0.0-0 and 2.0.1-rc.14. This flaw arises when accessing event.url properties, enabling an attacker to manipulate the Host header. The exploitation of this vulnerability permits a malicious user to bypass authentication or authorization checks in middleware, leading to potential unauthorized access to sensitive routes within applications built on H3, including Nitro/Nuxt. Immediate remediation is necessary, as version 2.0.1-rc.15 has addressed this issue.

Affected Version(s)

h3 >= 2.0.0-0, < 2.0.1-rc.15

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.