Junglewise Threat Intelligence

CVE-2026-33732: srvx middleware bypass via absolute URI in request line

CVE-2026-33732 · Severity: low · CVSS 3.1 · Published 2026-03-26

Vendors: npm.

Executive brief

srvx is a Node.js server framework component that routes HTTP requests and applies middleware such as authentication guards and rate limiters. Due to a URL parsing discrepancy, an attacker can craft a malicious HTTP request with a specially-formatted absolute URI to bypass route-based middleware protections, potentially gaining unauthorized access to protected endpoints. This requires direct network access to send raw HTTP requests, not possible through a web browser.

Technical details

The vulnerability is a pathname parsing discrepancy in srvx's FastURL parser (CWE-706: Use of Incorrectly-Resolved Name or Reference). When a raw HTTP request contains an absolute URI with a non-standard scheme (e.g., GET file://hehe?/internal/run HTTP/1.1), the FastURL manual parser incorrectly extracts the pathname as /internal/run, while the native URL parser would extract pathname as / with search ?/internal/run. This discrepancy allows an attacker to bypass middleware guards when a prior middleware triggers FastURL deoptimization (e.g., by accessing the hostname property), causing subsequent middleware to see a different pathname. The attack vector is network-based and requires sending a raw HTTP request, which cannot be performed from a browser. The fix (available in srvx 0.11.13) deopts FastURL to native URL for any string not starting with /, ensuring consistent pathname resolution across all middleware.

Affected products

  • h3js srvx < 0.11.13

Timeline

  • 2026-03-23: disclosed
  • 2026-03-26: patched: srvx 0.11.13 released with fix

References