Vercel Next.js
cpe:2.3:a:vercel:next.js:*:*:*:*:node.js:*:*
- >= 15.2.0, < 15.5.18
- >= 16.0.0, < 16.2.6
A vulnerability in Next.js middleware processing with Turbopack has been identified, allowing for proxy bypass in App Router applications. This issue arises because the fix for CVE-2026-44575 did not properly address middleware.ts when used with Turbopack. The vulnerability affects Next.js versions 15.2.0 prior to 15.5.18 and 16.0.0 prior to 16.2.6.
Exploitation of this vulnerability can lead to a proxy bypass, allowing unauthorized access to resources or segments of the application that should be restricted.
Users can upgrade to Next.js versions 15.5.18 or 16.2.6 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.