
CVE-2026-44373 and CVE-2026-44372 are issued. Reminder to upgrade and stay safe!
Post summary
The message simply names two CVEs and urges updates, without technical detail or evidence of exploitation.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. This vulnerability is fixed in 3.0.260429-beta.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-05-06 | 1 | Patch1 |
| 2026-05-13 | 1 | Disclosure1 |
| 2026-05-28 | 1 | Disclosure1 |

CVE-2026-44373 and CVE-2026-44372 are issued. Reminder to upgrade and stay safe!
Post summary
The message simply names two CVEs and urges updates, without technical detail or evidence of exploitation.

🟠 Nitro, Path Traversal Bypass, #CVE-2026-44373 (Medium) -DC-May2026-11 https://dailycve.com/nitro-path-traversal-bypass-cve-2026-44373-medium-dc-may2026-11/
Post summary
The post announces the discovery of a path traversal bypass in Nitro (CVE-2026-44373) with medium severity, but offers no PoC, exploit details, or remediation guidance.

CVE-2026-44373 Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in … https://www.cve.org/CVERecord?id=CVE-2026-44373
Post summary
A path‑traversal bypass in Nitro’s proxy routing, existing before version 3.0.260429-beta, has been disclosed via CVE‑2026‑44373. No PoC, exploit, or patch information is included.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | nitro | nitro | - | node.js | - |