CVE-2026-23527
EUVD-2026-273715.01.2026, 20:16
H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP Request Smuggling vulnerability. readRawBody is doing a strict case-sensitive check for the Transfer-Encoding header. It explicitly looks for "chunked", but per the RFC, this header should be case-insensitive. This vulnerability is fixed in 1.15.5.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| h3 | h3 | 𝑥 < 1.15.5 |
𝑥
= Vulnerable software versions