Detects H3 instances (including Nuxt/Nitro applications) running versions 2.0.0 through 2.0.1-rc.14 where the FastURL class in srvx constructs URLs from the untrusted Host header. An attacker can inject a path into the Host header to make middleware see a spoofed pathname, bypassing authentication and authorization checks on any middleware-protected route. Update H3 to 2.0.1-rc.15 or later.
Is your app exploitable through CVE-2026-33131?
Scan your domain free