๐Ÿ” CVE Alert

CVE-2026-44372

UNKNOWN 0.0

Nitro: Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cross-host redirect by sliding an extra slash in after the rule prefix. This vulnerability is fixed in 3.0.260429-beta.

CWE CWE-601
Vendor nitrojs
Product nitro
Published May 13, 2026
Stay Ahead of the Next One

Get instant alerts for nitrojs nitro

Be the first to know when new unknown vulnerabilities affecting nitrojs nitro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

nitrojs / nitro
< 3.0.260429-beta
nitrojs / nitropack
< 2.13.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/nitrojs/nitro/security/advisories/GHSA-9phm-9p8f-hw5m github.com: https://github.com/nitrojs/nitro/pull/4236 github.com: https://github.com/nitrojs/nitro/releases/tag/v2.13.4 github.com: https://github.com/nitrojs/nitro/releases/tag/v3.0.260429-beta