SSE Event Injection Vulnerability in H3 by h3js
CVE-2026-86252

6.9MEDIUM

Key Information:

Vendor

H3js

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-86252?

H3 versions prior to 1.15.9 are susceptible to an injection vulnerability that arises from inadequate sanitization of carriage return characters within EventStream data and comment fields. This flaw enables attackers to inject arbitrary Server-Sent Events (SSE) by including unsanitized carriage returns. As a result, attackers can introduce event type directives, divide single push calls into multiple browser-processed events, or bypass comment field protections, effectively overriding a previous fix that tackled newline injection. This creates potential risks for application integrity and user experience.

Affected Version(s)

h3 0 < 1.15.9

h3 2.0.0-beta.0 < 2.0.1-rc.17

h3 1.15.9

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.