CVE-2026-33129 | h3js h3 up to 2.0.0-rc.8/2.0.1-rc.9 requireBasicAuth timing discrepancy
VulDBArchived Mar 20, 2026✓ Full text saved
A vulnerability identified as problematic has been detected in h3js h3 up to 2.0.0-rc.8/2.0.1-rc.9 . This impacts the function requireBasicAuth . Performing a manipulation results in observable timing discrepancy. This vulnerability was named CVE-2026-33129 . The attack may be initiated remotely. There is no available exploit. You should upgrade the affected component.
Full text archived locally
✦ AI Summary· Claude Sonnet
VDB-352054 · CVE-2026-33129 · GCVE-0-2026-33129
H3JS H3 UP TO 2.0.0-RC.8/2.0.1-RC.9 REQUIREBASICAUTH TIMING DISCREPANCY
HISTORYDIFFRELATEJSONXMLCTI
CVSS Meta Temp Score Current Exploit Price (≈) CTI Interest Score
4.7 $0-$5k 2.69+
Summaryinfo
A vulnerability labeled as problematic has been found in h3js h3 up to 2.0.0-rc.8/2.0.1-rc.9. Affected is the function requireBasicAuth. Executing a manipulation can lead to timing discrepancy. The identification of this vulnerability is CVE-2026-33129. The attack may be launched remotely. There is no exploit available. The affected component should be upgraded.
Detailsinfo
A vulnerability classified as problematic was found in h3js h3 up to 2.0.0-rc.8/2.0.1-rc.9. This vulnerability affects the function requireBasicAuth. The manipulation with an unknown input leads to a timing discrepancy vulnerability. The CWE definition for the vulnerability is CWE-208. Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not. As an impact it is known to affect confidentiality. CVE summarizes:
H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability in the requireBasicAuth function due to the use of unsafe string comparison (!==). This allows an attacker to deduce the valid password character-by-character by measuring the server's response time, effectively bypassing password complexity protections. This issue is fixed in version 2.0.1-rc.9.
The advisory is available at github.com. This vulnerability was named CVE-2026-33129 since 03/17/2026. The exploitation appears to be difficult. The attack can be initiated remotely. No form of authentication is required for a successful exploitation. Technical details are known, but there is no available exploit. This vulnerability is assigned to T1592 by the MITRE ATT&CK project.
Upgrading to version 2.0.1-rc.9 eliminates this vulnerability.
Productinfo
Vendor
h3js
Name
h3
Version
2.0.0-rc.0
2.0.0-rc.1
2.0.0-rc.2
2.0.0-rc.3
2.0.0-rc.4
2.0.0-rc.5
2.0.0-rc.6
2.0.0-rc.7
2.0.0-rc.8
2.0.1-rc.0
2.0.1-rc.1
2.0.1-rc.2
2.0.1-rc.3
2.0.1-rc.4
2.0.1-rc.5
2.0.1-rc.6
2.0.1-rc.7
2.0.1-rc.8
2.0.1-rc.9
Website
Product: https://github.com/h3js/h3/
CPE 2.3info
🔒
🔒
🔒
CPE 2.2info
🔒
🔒
🔒
CVSSv4info
VulDB Vector: 🔒
VulDB Reliability: 🔍
CVSSv3info
VulDB Meta Base Score: 4.8
VulDB Meta Temp Score: 4.7
VulDB Base Score: 3.7
VulDB Temp Score: 3.6
VulDB Vector: 🔒
VulDB Reliability: 🔍
CNA Base Score: 5.9
CNA Vector (GitHub_M): 🔒
CVSSv2info
Vector Complexity Authentication Confidentiality Integrity Availability
Unlock Unlock Unlock Unlock Unlock Unlock
Unlock Unlock Unlock Unlock Unlock Unlock
Unlock Unlock Unlock Unlock Unlock Unlock
VulDB Base Score: 🔒
VulDB Temp Score: 🔒
VulDB Reliability: 🔍
Exploitinginfo
Class: Timing discrepancy
CWE: CWE-208 / CWE-203 / CWE-200
CAPEC: 🔒
ATT&CK: 🔒
Physical: No
Local: No
Remote: Yes
Availability: 🔒
Status: Not defined
Price Prediction: 🔍
Current Price Estimation: 🔒
0-Day Unlock Unlock Unlock Unlock
Today Unlock Unlock Unlock Unlock
Threat Intelligenceinfo
Interest: 🔍
Active Actors: 🔍
Active APT Groups: 🔍
Countermeasuresinfo
Recommended: Upgrade
Status: 🔍
0-Day Time: 🔒
Upgrade: h3 2.0.1-rc.9
Timelineinfo
03/17/2026 CVE reserved
03/20/2026 +3 days Advisory disclosed
03/20/2026 +0 days VulDB entry created
03/20/2026 +0 days VulDB entry last update
Sourcesinfo
Product: github.com
Advisory: github.com
Status: Confirmed
CVE: CVE-2026-33129 (🔒)
GCVE (CVE): GCVE-0-2026-33129
GCVE (VulDB): GCVE-100-352054
Entryinfo
Created: 03/20/2026 11:13
Changes: 03/20/2026 11:13 (63)
Complete: 🔍
Cache ID: 99:DC5:101
Discussion
No comments yet. Languages: en.
Please log in to comment.
◂ PreviousOverviewNext ▸