Skip to content

h3: SSE Event Injection via Unsanitized Carriage Return (`\r`) in EventStream Data and Comment Fields (Bypass of CVE Fix)

Moderate severity GitHub Reviewed Published Mar 20, 2026 in h3js/h3 • Updated Mar 20, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts