Junglewise Threat Intelligence

CVE-2026-44574: Vercel Next.js authorization bypass in dynamic route middleware

CVE-2026-44574 · Severity: high · CVSS 8.1 · Published 2026-05-13

Technologies: Red Hat Streams for Apache Kafka, Red Hat Enterprise Linux AI, Red Hat Trusted Artifact Signer, Vercel Next.js. Vendors: Red Hat, Vercel.

Executive brief

Next.js is a popular React framework used to build web applications. Applications using Next.js middleware to protect sensitive pages can be bypassed by attackers who craft special query parameters that trick the application into serving protected content without enforcing access controls. This could allow unauthorized users to view sensitive data or perform restricted actions.

Technical details

This vulnerability is an authentication bypass (CWE-288) affecting Next.js versions 15.4.0–15.5.15 and 16.0.0–16.2.4. The root cause is improper handling of dynamic route parameter normalization: externally supplied parameter encodings in query strings can alter how the page interprets the dynamic route value, bypassing middleware security checks that rely on path matching. The attack requires network access and low privileges (an ordinary unauthenticated request), with no user interaction necessary. An attacker can craft a request with malicious query parameters to access protected routes without triggering the middleware that should enforce authorization. Patches were released in versions 15.5.16 and 16.2.5, which restrict internal route-parameter normalization to trusted routing flows only.

Affected products

  • Vercel Next.js 15.4.0 to 15.5.15, 16.0.0 to 16.2.4

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: patched: Fixed in versions 15.5.16 and 16.2.5

References

Related threats