Nitro
Security Risk Profile
44
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 6 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 9, 2024 to present
6
Total CVEs
4
Critical+High
0
Exploited
4
Unpatched
Threat Assessment
Avg CVSS
7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
44/100
medium
Severity Distribution
Critical
0High
4Medium
2Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Null Pointer Dereference
2
2
Path Traversal
1
3
Use After Free
1
Most Affected Products
1. Nitro Nitro PDF Pro for Windows3
2. Gonitro Nitro Pdf Pro3
3. npm/nitropack2
4. npm/nitro2
5. Nitro Nitro2
Recent Vulnerabilities
See more →CVE-2026-44372
CVSS 5.3medium
Nitro: Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules
5/6/2026
CVE-2026-44373
CVSS 5.3medium
Nitro: Proxy scope bypass via percent-encoded path traversal in `routeRules`
5/6/2026
CVE-2025-69627
CVSS 8.4high
4/13/2026🔧 No Patch
CVE-2025-66769
CVSS 7.5high
4/13/2026🔧 No Patch
CVE-2025-69624
CVSS 7.5high
4/13/2026🔧 No Patch
CVE-2024-35288
CVSS 7.8high
10/9/2024🔧 No Patch
Monitor Nitro in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.