Description
srvx is a universal server based on web standards. Prior to version 0.11.13, a pathname parsing discrepancy in srvx's `FastURL` allows middleware bypass on the Node.js adapter when a raw HTTP request uses an absolute URI with a non-standard scheme (e.g. `file://`). Starting in version 0.11.13, the `FastURL` constructor now deopts to native `URL` for any string not starting with `/`, ensuring consistent pathname resolution.
INFO
Published Date :
2026-03-26T17:21:15.709Z
Last Modified :
2026-03-27T14:41:11.864Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-33732 vulnerability.
| Vendors | Products |
|---|---|
| H3js |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-33732.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact