CVE-2026-33732 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

srvx is a universal server based on web standards. Prior to version 0.11.13, a pathname parsing discrepancy in srvx's `FastURL` allows middleware bypass on the…
Medium CVSS: 4.8

CVE-2026-33732

srvx is a universal server based on web standards. Prior to version 0.11.13, a pathname parsing discrepancy in srvx's `FastURL` allows middleware bypass on the Node.js adapter when a raw HTTP request uses an absolute URI with a non-standard scheme (e.g. `file://`). Starting in version 0.11.13, the `FastURL` constructor now deopts to native `URL` for any string not starting with `/`, ensuring consistent pathname resolution.
Vendor
H3
Product
Srvx
CWE
CWE-706
Yayın Tarihi
2026-03-26 18:16:31
Güncelleme
2026-04-02 18:41:11
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar