CVE-2026-44373

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. This vulnerability is fixed in 3.0.260429-beta.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nitro:nitro:*:*:*:*:*:node.js:*:*
cpe:2.3:a:nitro:nitro:*:*:*:*:*:node.js:*:*

History

28 May 2026, 18:22

Type Values Removed Values Added
CPE cpe:2.3:a:nitro:nitro:*:*:*:*:*:node.js:*:*
First Time Nitro nitro
Nitro
References () https://github.com/nitrojs/nitro/pull/4222 - () https://github.com/nitrojs/nitro/pull/4222 - Issue Tracking, Patch
References () https://github.com/nitrojs/nitro/pull/4223 - () https://github.com/nitrojs/nitro/pull/4223 - Issue Tracking, Patch
References () https://github.com/nitrojs/nitro/releases/tag/v2.13.4 - () https://github.com/nitrojs/nitro/releases/tag/v2.13.4 - Release Notes
References () https://github.com/nitrojs/nitro/releases/tag/v3.0.260429-beta - () https://github.com/nitrojs/nitro/releases/tag/v3.0.260429-beta - Release Notes
References () https://github.com/nitrojs/nitro/security/advisories/GHSA-5w89-w975-hf9q - () https://github.com/nitrojs/nitro/security/advisories/GHSA-5w89-w975-hf9q - Third Party Advisory

13 May 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 21:16

Updated : 2026-05-28 18:22


NVD link : CVE-2026-44373

Mitre link : CVE-2026-44373

CVE.ORG link : CVE-2026-44373


JSON object : View

Products Affected

nitro

  • nitro
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')