Логотип exploitDog
bind:CVE-2026-23527
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-23527

Количество 2

Количество 2

nvd логотип

CVE-2026-23527

4 дня назад

H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP Request Smuggling vulnerability. readRawBody is doing a strict case-sensitive check for the Transfer-Encoding header. It explicitly looks for "chunked", but per the RFC, this header should be case-insensitive. This vulnerability is fixed in 1.15.5.

CVSS3: 8.9
EPSS: Низкий
github логотип

GHSA-mp2g-9vg9-f4cg

4 дня назад

h3 v1 has Request Smuggling (TE.TE) issue

CVSS3: 8.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-23527

H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP Request Smuggling vulnerability. readRawBody is doing a strict case-sensitive check for the Transfer-Encoding header. It explicitly looks for "chunked", but per the RFC, this header should be case-insensitive. This vulnerability is fixed in 1.15.5.

CVSS3: 8.9
0%
Низкий
4 дня назад
github логотип
GHSA-mp2g-9vg9-f4cg

h3 v1 has Request Smuggling (TE.TE) issue

CVSS3: 8.9
0%
Низкий
4 дня назад

Уязвимостей на страницу