SSE Event Injection Vulnerability in H3 by h3js
CVE-2026-86252
6.9MEDIUM
What is CVE-2026-86252?
H3 versions prior to 1.15.9 are susceptible to an injection vulnerability that arises from inadequate sanitization of carriage return characters within EventStream data and comment fields. This flaw enables attackers to inject arbitrary Server-Sent Events (SSE) by including unsanitized carriage returns. As a result, attackers can introduce event type directives, divide single push calls into multiple browser-processed events, or bypass comment field protections, effectively overriding a previous fix that tackled newline injection. This creates potential risks for application integrity and user experience.
Affected Version(s)
h3 0 < 1.15.9
h3 2.0.0-beta.0 < 2.0.1-rc.17
h3 1.15.9
