h3
28 known vulnerabilities · 0 critical · 0 high
h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read
h3: SSE Event Injection via Unsanitized Carriage Return (`\r`) in EventStream Data and Comment Fields (Bypass of CVE Fix)
h3: Double Decoding in `serveStatic` Bypasses `resolveDotSegments` Path Traversal Protection via `%252e%252e`
h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields
H3: Unbounded Chunked Cookie Count in Session Cleanup Loop may Lead to Denial of Service
H3 has an Open Redirect via Protocol-Relative Path in redirectBack() Referer Validation
h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes
Malicious code in calc_a55qzguqh3 (npm)
Malicious code in myapp-by-7h3n00b (npm)
Malicious code in wb-eth3 (npm)
Malicious code in down-load-available-zip-now-35816-laughter-lust-jih3q-fajkvi (npm)
Malicious code in h3-next (npm)
Malicious code in lorash3fset (npm)
Malicious code in asdfgh33 (npm)
Malicious code in sturdyfetch3 (npm)
Malicious code in zip-mp3-a-lbum-do-wnload-new-gift-of-screws-q2h3s-xswcix (npm)
Malicious code in asdfgh3 (npm)
Malicious code in nebulagl-h3-hexagon-editing (npm)
Malicious code in h3-website (npm)
Malicious code in @tauh33dkhan/alloy-icons (npm)
Malicious code in fca-priyansh3 (npm)
Malicious code in h3-jsv3 (npm)
Malicious code in vh3 (npm)
Malicious code in 7h3n00b2 (npm)
Malicious code in initial-path32 (npm)