CVE-2026-44373

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. This vulnerability is fixed in 3.0.260429-beta.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nitro:nitro:*:*:*:*:*:node.js:*:*
cpe:2.3:a:nitro:nitro:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-05-13 21:16

Updated : 2026-06-17 10:50


NVD link : CVE-2026-44373

Mitre link : CVE-2026-44373

CVE.ORG link : CVE-2026-44373


JSON object : View

Products Affected

nitro

  • nitro
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')