nextjs - 💡(How to fix) Fix [Security] Critical Nitro.js auth bypass — CVE-2026-33131 bypass, requesting private channel

Official PRs (…)
ON THIS PAGE

Recommended Tools

×6

Utilities matched from this issue’s tags and category — try them while you read without losing context.

GitHub issue graph ai analysis

Paste a GitHub issue URL. We fetch that issue, discover linked issues from bodies/comments/timeline, collect linked pull requests, and produce a structured English report.

The report is written in English Markdown for sharing and archival.

Helpful · Quick feedback

Loading…
RAW_BUFFERClick to expand / collapse

Hi Vercel Security Team,

I discovered a CRITICAL authentication bypass vulnerability in Nitro.js (CVE-2026-33131 bypass via %2f encoding) that affects all Nitro.js versions through 2.11.0 and all deployed Vercel apps using Nitro.

The vulnerability allows unauthenticated access to any protected API route by encoding the path separator in the URL (%2f). This is a BYPASS of the recently-closed GHSA-mq72-q3r4-gvff (CVE-2026-33131).

I attempted to submit via:

  • HackerOne: Account Signal pending
  • [email protected]: SMTP blocked from my VPS
  • nitrojs/nitro: No private vuln reporting enabled

Full PoC and fix recommendation ready. Please provide a private channel and I will share immediately.

GitHub: @xiaoyaoyou2 Email: [email protected] H1: xiaoyao-sec

Vote matrix · Quick signals

Works
Did the solution work? Tap to confirm.
Easy Fix
Was it a quick fix?
Time Saver
Did it save you time?
Blocking
Was it severely blocking?
Common Issue
Are others likely hitting this too?
Flaky / Intermittent
Is it intermittent?
Verified / Reproducible
Can you reproduce it reliably?
Loading…

Still need to ship something?

×6

Another batch ranked right after the header list — different links, same matching logic.

Back to top recommendations

TRENDING