Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5w89-w975-hf9q | Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules` |
Thu, 14 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nitrojs
Nitrojs nitro Nitrojs nitropack |
|
| Vendors & Products |
Nitrojs
Nitrojs nitro Nitrojs nitropack |
Thu, 14 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. This vulnerability is fixed in 3.0.260429-beta. | |
| Title | Nitro: Proxy scope bypass via percent-encoded path traversal in `routeRules` | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-14T13:16:50.542Z
Reserved: 2026-05-05T20:15:20.631Z
Link: CVE-2026-44373
Updated: 2026-05-14T13:12:29.892Z
Status : Undergoing Analysis
Published: 2026-05-13T21:16:48.033
Modified: 2026-05-14T16:57:26.740
Link: CVE-2026-44373
No data.
OpenCVE Enrichment
Updated: 2026-05-14T14:33:30Z
Github GHSA