GHSA-p36q-q72m-gchr

Suggest an improvement
Source
https://github.com/advisories/GHSA-p36q-q72m-gchr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-p36q-q72m-gchr/GHSA-p36q-q72m-gchr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p36q-q72m-gchr
Aliases
Published
2026-03-26T16:52:08Z
Modified
2026-03-27T21:20:00Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
srvx is vulnerable to middleware bypass via absolute URI in request line
Details

Summary

A pathname parsing discrepancy in srvx's FastURL allows middleware bypass on the Node.js adapter when a raw HTTP request uses an absolute URI with a non-standard scheme (e.g. file://).

Details

When Node.js receives an absolute URI in the request line (e.g. GET file://hehe?/internal/run HTTP/1.1), req.url is set verbatim to file://hehe?/internal/run. Since this doesn't start with /, NodeRequestURL passes it directly to FastURL as a string, which stores it in #href for lazy manual parsing.

FastURL#getPos() locates the pathname by finding :// then scanning for the next / — but this fails for URLs like file://hehe?/internal/run where a ? appears before the first / after the authority. The manual parser extracts pathname as /internal/run, while native URL correctly parses it as pathname / with search ?/internal/run.

This discrepancy means the router (using the fast-path) matches /internal/run, but if any middleware triggers a deopt to native URL (e.g. by accessing hostname), subsequent middleware sees a different pathname — bypassing route-based middleware guards.

This is a bypass of CVE-2026-33131.

Impact

Route-based middleware (auth guards, rate limiters, etc.) can be bypassed on the Node.js adapter when a prior middleware triggers FastURL deopt. Requires sending a raw HTTP request (not possible from browsers).

Fix

srvx FastURL constructor now deopts to native URL for any string not starting with /, ensuring consistent pathname resolution.

Database specific
{
    "cwe_ids":  [
        "CWE-706"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-26T16:52:08Z",
    "nvd_published_at":  "2026-03-26T18:16:31Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / srvx

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.11.13

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-p36q-q72m-gchr/GHSA-p36q-q72m-gchr.json"