<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T21:33:21.798678+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318487</id>
    <title>EUVD-2026-318487</title>
    <updated>2026-10-08T21:33:21.800993+00:00</updated>
    <content>EUVD-2026-318487</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318487"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44373</id>
    <title>fkie_cve-2026-44373</title>
    <updated>2026-10-08T21:33:21.801024+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. This vulnerability is fixed in 3.0.260429-beta.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5w89-w975-hf9q</id>
    <title>GHSA-5w89-w975-hf9q — Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules`</title>
    <updated>2026-10-08T21:33:21.801054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: nitro, npm: nitropack</p>
<p>A proxy route rule like:</p>
<p>```ts
routeRules: {
  "/api/orders/**": { proxy: { to: "http://upstream/orders/**" } }
}
```</p>
<p>is intended to limit the proxy to URLs under `/api/orders/`. Before the patch, an attacker could bypass that scope by sending percent-encoded path traversal (`..%2f`) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. Example exploit:</p>
<p>```
GET /api/orders/..%2fadmin%2fconfig.json
```</p>
<p>Nitro sees `..%2f` as opaque characters at match time, the `/api/orders/**` rule matched, and the raw path was forwarded to the upstream as `/orders/..%2fadmin/config.json`. An upstream that decodes `%2F` to  `/` then resolved `..` and can serve `/admin/config.json` outside the intended scope.</p>
<p>### Are you affected?</p>
<p>Users may be affected if **ALL** of the following are true:</p>
<p>1. Their project uses Nitro's `routeRules` with a `proxy` entry (`{ proxy: { to: "..." } }`).
2. The proxy `to` value uses a `/**` wildcard suffix to forward sub-paths.
3. The **upstream** behind the proxy decodes `%2F` as `/` before routing or filesystem lookup.
4. Proxy route rules are _not_ handled natively at CDN (nitro v3 and vercel)</p>
<p>Whether the bypass actually leaks data depends on the upstream. Modern JS frameworks keep `%2F` opaque per RFC 3986 and are safe by construction.</p>
<p>- **Safe examples:** H3 v2, Express v5, Hono v4 — modern JS frameworks keep `%2F` opaque per RFC 3986.
- **Vulnerable examples:** naive imlementations that decodes the UR…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5w89-w975-hf9q"/>
  </entry>
</feed>
