PT-2026-38253 · Nitro · Nitro

CVE-2026-44373

·

Published

2026-05-06

·

Updated

2026-05-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nitro versions prior to 2.13.4 Nitro versions prior to 3.0.260429-beta
Description An attacker can bypass proxy route rules by sending percent-encoded path traversal sequences (..%2f) in the URL. This occurs when Nitro treats these characters as opaque during matching, allowing a request to match a rule like "/api/orders/**" and be forwarded to an upstream server. If the upstream server decodes %2F as / before routing or filesystem lookup, it may resolve the path outside the intended scope, potentially exposing internal admin endpoints, secrets, or other restricted services.
Recommendations Update to version 2.13.4 or later. Update to version 3.0.260429-beta or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44373
GHSA-5W89-W975-HF9Q

Affected Products

Nitro