Junglewise Threat Intelligence

CVE-2026-40299: next-intl has an open redirect vulnerability

CVE-2026-40299 · Severity: medium · CVSS 4 · Published 2026-04-10

Technologies: Amannn Next-Intl. Vendors: npm.

Executive brief

next-intl is a library used to add internationalization (multi-language support) to Next.js applications. When using the middleware with a specific configuration option, attackers can craft malicious URLs that trick the application into redirecting users to external websites while appearing to originate from the trusted app. This could be used for credential theft, malware distribution, or phishing attacks.

Technical details

The vulnerability is a classic open redirect (CWE-601) in the next-intl middleware when configured with localePrefix: 'as-needed'. The root cause lies in improper handling of relative redirect targets during path parsing; the WHATWG URL parser resolves scheme-relative URLs (e.g., //) or URLs with control characters that are stripped by the parser to external hosts. An attacker can construct a malicious URL that, when processed by the middleware, redirects the browser off-site while the initial request appears to originate from the trusted application. The vulnerability affects all versions prior to 4.9.1 and requires no authentication or user interaction beyond clicking a link. A patch is available in next-intl version 4.9.1.

Affected products

  • amannn next-intl < 4.9.1

Timeline

  • 2026-04-10: disclosed
  • 2026-04-10: patched: Fixed in next-intl 4.9.1

References

Related threats