All verified exploits

CVE-2026-33131 Middleware Bypass via Forged Host Header

Deterministic high H3 Added cve-verified-cve-2026-33131

Detects H3 instances (including Nuxt/Nitro applications) running versions 2.0.0 through 2.0.1-rc.14 where the FastURL class in srvx constructs URLs from the untrusted Host header. An attacker can inject a path into the Host header to make middleware see a spoofed pathname, bypassing authentication and authorization checks on any middleware-protected route. Update H3 to 2.0.1-rc.15 or later.

Is your app exploitable through CVE-2026-33131?

Scan your domain free