CVE-2026-33242 | salvo-rs salvo up to 0.89.2 encode_url_path path traversal (GHSA-f842-phm9-p4v4 / CNNVD-202603-4631)
A vulnerability was found in salvo-rs salvo up to 0.89.2. It has been declared as critical. Impacted is the function encode_url_path. Such manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-33242. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.