Host Header Spoofing Vulnerability in H3 Framework by H3
CVE-2026-33131
7.4HIGH
What is CVE-2026-33131?
The H3 framework, which serves as a minimal H(TTP) framework, contains a vulnerability that allows for host header spoofing between versions 2.0.0-0 and 2.0.1-rc.14. This flaw arises when accessing event.url properties, enabling an attacker to manipulate the Host header. The exploitation of this vulnerability permits a malicious user to bypass authentication or authorization checks in middleware, leading to potential unauthorized access to sensitive routes within applications built on H3, including Nitro/Nuxt. Immediate remediation is necessary, as version 2.0.1-rc.15 has addressed this issue.
Affected Version(s)
h3 >= 2.0.0-0, < 2.0.1-rc.15
