Security Advisory

CVE-2026-44373

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-13 20:26:28
Last updated 2026-05-14 13:16:50
Assigner GitHub_M
CVSS score 5.3
State PUBLISHED

Description

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. This vulnerability is fixed in 3.0.260429-beta.