CVE-2026-44373Disclosure(nitro / nitro)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nitro nitro systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. This vulnerability is fixed in 3.0.260429-beta.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nitro

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-06); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
nitro

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-06: 1Mentions · 2026-05-13: 1Mentions · 2026-05-28: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-28: 105-0605-1305-28
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-061
Patch1
2026-05-131
Disclosure1
2026-05-281
Disclosure1
Full discourse3 posts
  • Pooya Parsa 🦋@_pi0_
    Patch

    CVE-2026-44373 and CVE-2026-44372 are issued. Reminder to upgrade and stay safe!

    Post summary

    The message simply names two CVEs and urges updates, without technical detail or evidence of exploitation.

    0504246.6K
    13.6K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Nitro, Path Traversal Bypass, #CVE-2026-44373 (Medium) -DC-May2026-11 https://dailycve.com/nitro-path-traversal-bypass-cve-2026-44373-medium-dc-may2026-11/

    Post summary

    The post announces the discovery of a path traversal bypass in Nitro (CVE-2026-44373) with medium severity, but offers no PoC, exploit details, or remediation guidance.

    0000058
    207 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44373 Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in … https://www.cve.org/CVERecord?id=CVE-2026-44373

    Post summary

    A path‑traversal bypass in Nitro’s proxy routing, existing before version 3.0.260429-beta, has been disclosed via CVE‑2026‑44373. No PoC, exploit, or patch information is included.

    00000151
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnitronitro-node.js-

Explore more