<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 21:32:14 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-318487</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-318487</link>
      <description>EUVD-2026-318487</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-318487</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44373</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44373</link>
      <description>&lt;p&gt;Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. This vulnerability is fixed in 3.0.260429-beta.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. This vulnerability is fixed in 3.0.260429-beta.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44373</guid>
    </item>
    <item>
      <title>GHSA-5w89-w975-hf9q — Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5w89-w975-hf9q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nitro, npm: nitropack&lt;/p&gt;
&lt;p&gt;A proxy route rule like:&lt;/p&gt;
&lt;p&gt;```ts
routeRules: {
  &amp;#34;/api/orders/**&amp;#34;: { proxy: { to: &amp;#34;http://upstream/orders/**&amp;#34; } }
}
```&lt;/p&gt;
&lt;p&gt;is intended to limit the proxy to URLs under `/api/orders/`. Before the patch, an attacker could bypass that scope by sending percent-encoded path traversal (`..%2f`) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. Example exploit:&lt;/p&gt;
&lt;p&gt;```
GET /api/orders/..%2fadmin%2fconfig.json
```&lt;/p&gt;
&lt;p&gt;Nitro sees `..%2f` as opaque characters at match time, the `/api/orders/**` rule matched, and the raw path was forwarded to the upstream as `/orders/..%2fadmin/config.json`. An upstream that decodes `%2F` to  `/` then resolved `..` and can serve `/admin/config.json` outside the intended scope.&lt;/p&gt;
&lt;p&gt;### Are you affected?&lt;/p&gt;
&lt;p&gt;Users may be affected if **ALL** of the following are true:&lt;/p&gt;
&lt;p&gt;1. Their project uses Nitro&amp;#39;s `routeRules` with a `proxy` entry (`{ proxy: { to: &amp;#34;...&amp;#34; } }`).
2. The proxy `to` value uses a `/**` wildcard suffix to forward sub-paths.
3. The **upstream** behind the proxy decodes `%2F` as `/` before routing or filesystem lookup.
4. Proxy route rules are _not_ handled natively at CDN (nitro v3 and vercel)&lt;/p&gt;
&lt;p&gt;Whether the bypass actually leaks data depends on the upstream. Modern JS frameworks keep `%2F` opaque per RFC 3986 and are safe by construction.&lt;/p&gt;
&lt;p&gt;- **Safe examples:** H3 v2, Express v5, Hono v4 — modern JS frameworks keep `%2F` opaque per RFC 3986.
- **Vulnerable examples:** naive imlementations that decodes the UR…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nitro, npm: nitropack&lt;/p&gt;
&lt;p&gt;A proxy route rule like:&lt;/p&gt;
&lt;p&gt;```ts
routeRules: {
  &amp;#34;/api/orders/**&amp;#34;: { proxy: { to: &amp;#34;http://upstream/orders/**&amp;#34; } }
}
```&lt;/p&gt;
&lt;p&gt;is intended to limit the proxy to URLs under `/api/orders/`. Before the patch, an attacker could bypass that scope by sending percent-encoded path traversal (`..%2f`) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. Example exploit:&lt;/p&gt;
&lt;p&gt;```
GET /api/orders/..%2fadmin%2fconfig.json
```&lt;/p&gt;
&lt;p&gt;Nitro sees `..%2f` as opaque characters at match time, the `/api/orders/**` rule matched, and the raw path was forwarded to the upstream as `/orders/..%2fadmin/config.json`. An upstream that decodes `%2F` to  `/` then resolved `..` and can serve `/admin/config.json` outside the intended scope.&lt;/p&gt;
&lt;p&gt;### Are you affected?&lt;/p&gt;
&lt;p&gt;Users may be affected if **ALL** of the following are true:&lt;/p&gt;
&lt;p&gt;1. Their project uses Nitro&amp;#39;s `routeRules` with a `proxy` entry (`{ proxy: { to: &amp;#34;...&amp;#34; } }`).
2. The proxy `to` value uses a `/**` wildcard suffix to forward sub-paths.
3. The **upstream** behind the proxy decodes `%2F` as `/` before routing or filesystem lookup.
4. Proxy route rules are _not_ handled natively at CDN (nitro v3 and vercel)&lt;/p&gt;
&lt;p&gt;Whether the bypass actually leaks data depends on the upstream. Modern JS frameworks keep `%2F` opaque per RFC 3986 and are safe by construction.&lt;/p&gt;
&lt;p&gt;- **Safe examples:** H3 v2, Express v5, Hono v4 — modern JS frameworks keep `%2F` opaque per RFC 3986.
- **Vulnerable examples:** naive imlementations that decodes the UR…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5w89-w975-hf9q</guid>
    </item>
  </channel>
</rss>
