CVE-2026-33732Disclosure(h3 / srvx)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

srvx is a universal server based on web standards. Prior to version 0.11.13, a pathname parsing discrepancy in srvx's `FastURL` allows middleware bypass on the Node.js adapter when a raw HTTP request uses an absolute URI with a non-standard scheme (e.g. `file://`). Starting in version 0.11.13, the `FastURL` constructor now deopts to native `URL` for any string not starting with `/`, ensuring consistent pathname resolution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-706

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • srvx

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
srvx

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-26: 3Technical Details · 2026-03-26: 303-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33732 srvx is a universal server based on web standards. Prior to version 0.11.13, a pathname parsing discrepancy in srvx's `FastURL` allows middleware bypass on the Node.j… https://www.cve.org/CVERecord?id=CVE-2026-33732

    Post summary

    The CVE-2026-33732 disclosure reveals a pathname parsing flaw in srvx’s FastURL that permits middleware bypass before version 0.11.13; no PoC, exploit, patch, or exploitation evidence is provided.

    00010198
    56.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33732 srvx is a universal server based on web standards. Prior to version 0.11.13, a pathname parsing discrepancy in srvx's `FastURL` allows middleware bypass on the Node.j… https://www.cve.org/CVERecord?id=CVE-2026-33732 ----- Traducción: CVE-2026-33732 srv… http://infoflow.cloud`

    Post summary

    The tweet announces a pathname parsing flaw in srvx's FastURL that permits middleware bypass, but offers no PoC, exploit code, or patch information.

    0000039
    65 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33732 - srvx is vulnerable to middleware bypass via absolute URI in request line Intel Report: https://ift.tt/oQpjiJH

    Post summary

    The tweet alerts about CVE-2026-33732, describing a middleware bypass vulnerability in srvx due to absolute URI handling.

    0000029
    285 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apph3srvx-node.js-

Explore more