Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-16
2 active CVEs reported via OSV.dev
Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules`
Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules
Get SLA-backed support, security patches, and direct access to senior engineers for Nitro — without relying on volunteer maintainers.
Talk to an Expert →