
I have identified a Path Traversal and Access Control Bypass vulnerability in the Salvo Rust framework, now officially tracked as CVE-2026-33242. The vulnerability exists in the salvo-proxy component due to improper URL path normalization in the encode_url_path function. This allows unauthenticated attackers to bypass gateway routing constraints and access protected backend endpoints via dot-sequence payloads. The issue has been patched in Salvo v0.89.3. 🔗Technical Advisory: https://github.com/salvo-rs/salvo/security/advisories/GHSA-f842-phm9-p4v4 #RustLang #CVE #VulnerabilityResearch
Post summary
The post announces CVE-2026-33242, details a path traversal and access control bypass in Salvo, and notes that it has been fixed in v0.89.3 via a linked advisory.



