CVE-2026-33129: h3

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability in the requireBasicAuth function due to the use of unsafe string comparison (!==). This allows an attacker to deduce the valid password character-by-character by measuring the server's response time, effectively bypassing password complexity protections. This issue is fixed in version 2.0.1-rc.9.

Affected products

  • h3 h3: version 2.0.0 only; version 2.0.1 only

Published 2026-03-20. Last modified 2026-06-17.