Executive brief
Next.js is a popular React framework used to build web applications. Applications using Next.js middleware to protect sensitive pages can be bypassed by attackers who craft special query parameters that trick the application into serving protected content without enforcing access controls. This could allow unauthorized users to view sensitive data or perform restricted actions.
Technical details
This vulnerability is an authentication bypass (CWE-288) affecting Next.js versions 15.4.0–15.5.15 and 16.0.0–16.2.4. The root cause is improper handling of dynamic route parameter normalization: externally supplied parameter encodings in query strings can alter how the page interprets the dynamic route value, bypassing middleware security checks that rely on path matching. The attack requires network access and low privileges (an ordinary unauthenticated request), with no user interaction necessary. An attacker can craft a request with malicious query parameters to access protected routes without triggering the middleware that should enforce authorization. Patches were released in versions 15.5.16 and 16.2.5, which restrict internal route-parameter normalization to trusted routing flows only.
Affected products
- Vercel Next.js 15.4.0 to 15.5.15, 16.0.0 to 16.2.4
Timeline
- 2026-05-06: disclosed
- 2026-05-06: patched: Fixed in versions 15.5.16 and 16.2.5