CVE-2026-33129
EUVD-2026-1366820.03.2026, 10:16
H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability in the requireBasicAuth function due to the use of unsafe string comparison (!==). This allows an attacker to deduce the valid password character-by-character by measuring the server's response time, effectively bypassing password complexity protections. This issue is fixed in version 2.0.1-rc.9.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| h3 | h3 | 2.0.0 |
| h3 | h3 | 2.0.1:rc1 |
| h3 | h3 | 2.0.1:rc2 |
| h3 | h3 | 2.0.1:rc3 |
| h3 | h3 | 2.0.1:rc4 |
| h3 | h3 | 2.0.1:rc5 |
| h3 | h3 | 2.0.1:rc6 |
| h3 | h3 | 2.0.1:rc7 |
| h3 | h3 | 2.0.1:rc8 |
𝑥
= Vulnerable software versions