
CVE-2026-33732 srvx is a universal server based on web standards. Prior to version 0.11.13, a pathname parsing discrepancy in srvx's `FastURL` allows middleware bypass on the Node.j… https://www.cve.org/CVERecord?id=CVE-2026-33732
Post summary
The CVE-2026-33732 disclosure reveals a pathname parsing flaw in srvx’s FastURL that permits middleware bypass before version 0.11.13; no PoC, exploit, patch, or exploitation evidence is provided.


