<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 02:33:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-318542</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-318542</link>
      <description>EUVD-2026-318542</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-318542</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44372</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44372</link>
      <description>&lt;p&gt;Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cross-host redirect by sliding an extra slash in after the rule prefix. This vulnerability is fixed in 3.0.260429-beta.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cross-host redirect by sliding an extra slash in after the rule prefix. This vulnerability is fixed in 3.0.260429-beta.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44372</guid>
    </item>
    <item>
      <title>GHSA-9phm-9p8f-hw5m — Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9phm-9p8f-hw5m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nitro, npm: nitropack&lt;/p&gt;
&lt;p&gt;A redirect route rule like:&lt;/p&gt;
&lt;p&gt;```ts
routeRules: {
  &amp;#34;/legacy/**&amp;#34;: { redirect: &amp;#34;/**&amp;#34; }
}
```&lt;/p&gt;
&lt;p&gt;is intended to rewrite paths within the same host. Before the patch, an attacker could turn the rewrite into a cross-host redirect by sliding an extra slash in after the rule prefix. Example exploit:&lt;/p&gt;
&lt;p&gt;```
GET /legacy//evil.com
```&lt;/p&gt;
&lt;p&gt;Nitro stripped `/legacy` from the matched pathname and joined the remainder against the rule&amp;#39;s target. The remainder was `//evil.com`, which the join preserved verbatim, so Nitro responded with `Location: //evil.com`. Browsers resolve `//evil.com` as a protocol-relative URL against the current scheme, sending the user to `https://evil.com`.&lt;/p&gt;
&lt;p&gt;### Are you affected?&lt;/p&gt;
&lt;p&gt;Users may be affected if **all** of the following are true:&lt;/p&gt;
&lt;p&gt;1. Their project uses Nitro&amp;#39;s `routeRules` with a `redirect` entry.
2. The target uses a `/**` wildcard suffix to forward sub-paths (e.g. `redirect: &amp;#34;/**&amp;#34;`, `redirect: &amp;#34;/new/**&amp;#34;`, `proxy: { to: &amp;#34;http://upstream/**&amp;#34; }`).
3. The `redirect` rule is _not_ handled natively at the CDN layer. The `vercel`, `netlify`, `cloudflare-pages`, and `edgeone` presets translate `routeRules.redirect` into platform config (`vercel.json`, `_redirects`, EdgeOne v3 config) and serve the redirect at the edge — those deployments bypass the Nitro runtime entirely and are not affected. Every other preset executes the redirect through the Nitro runtime and can be vulnerable.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Open redirect from any host serving Nitro with a wildcard `redirect` rule. Th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nitro, npm: nitropack&lt;/p&gt;
&lt;p&gt;A redirect route rule like:&lt;/p&gt;
&lt;p&gt;```ts
routeRules: {
  &amp;#34;/legacy/**&amp;#34;: { redirect: &amp;#34;/**&amp;#34; }
}
```&lt;/p&gt;
&lt;p&gt;is intended to rewrite paths within the same host. Before the patch, an attacker could turn the rewrite into a cross-host redirect by sliding an extra slash in after the rule prefix. Example exploit:&lt;/p&gt;
&lt;p&gt;```
GET /legacy//evil.com
```&lt;/p&gt;
&lt;p&gt;Nitro stripped `/legacy` from the matched pathname and joined the remainder against the rule&amp;#39;s target. The remainder was `//evil.com`, which the join preserved verbatim, so Nitro responded with `Location: //evil.com`. Browsers resolve `//evil.com` as a protocol-relative URL against the current scheme, sending the user to `https://evil.com`.&lt;/p&gt;
&lt;p&gt;### Are you affected?&lt;/p&gt;
&lt;p&gt;Users may be affected if **all** of the following are true:&lt;/p&gt;
&lt;p&gt;1. Their project uses Nitro&amp;#39;s `routeRules` with a `redirect` entry.
2. The target uses a `/**` wildcard suffix to forward sub-paths (e.g. `redirect: &amp;#34;/**&amp;#34;`, `redirect: &amp;#34;/new/**&amp;#34;`, `proxy: { to: &amp;#34;http://upstream/**&amp;#34; }`).
3. The `redirect` rule is _not_ handled natively at the CDN layer. The `vercel`, `netlify`, `cloudflare-pages`, and `edgeone` presets translate `routeRules.redirect` into platform config (`vercel.json`, `_redirects`, EdgeOne v3 config) and serve the redirect at the edge — those deployments bypass the Nitro runtime entirely and are not affected. Every other preset executes the redirect through the Nitro runtime and can be vulnerable.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Open redirect from any host serving Nitro with a wildcard `redirect` rule. Th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9phm-9p8f-hw5m</guid>
    </item>
  </channel>
</rss>
