CVE-2026-44372Patch(nitro / nitro)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nitro nitro systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cross-host redirect by sliding an extra slash in after the rule prefix. This vulnerability is fixed in 3.0.260429-beta.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nitro

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-06); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
nitro

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-06: 1Mentions · 2026-05-13: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-13: 105-0605-13
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-061
Patch1
2026-05-131
Disclosure1
Full discourse2 posts
  • Pooya Parsa 🦋@_pi0_
    Patch

    CVE-2026-44373 and CVE-2026-44372 are issued. Reminder to upgrade and stay safe!

    Post summary

    The post announces the issuance of CVE‑2026‑44373 and CVE‑2026‑44372 and urges users to apply updates to mitigate the risk. No further technical or exploit details are provided.

    0504246.6K
    13.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44372 Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cross-host redirect b… https://www.cve.org/CVERecord?id=CVE-2026-44372

    Post summary

    The tweet discloses a redirect-based cross-host redirect flaw in Nitro server kit, noting that an attacker could exploit wildcard rewrite rules prior to version 3.0.260429-beta.

    00000134
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnitronitro---

Explore more