CVE-2026-33128 | h3js h3 up to 1.15.5 SSE Message formatEventStreamMessage id/event/data/comment crlf injection
A vulnerability has been found in h3js h3 up to 1.15.5 and classified as problematic. This vulnerability affects the function formatEventStreamMessage of the component SSE Message Handler. Performing a manipulation of the argument id/event/data/comment results in crlf injection.
This vulnerability is reported as CVE-2026-33128. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.