Junglewise Threat Intelligence

CVE-2026-45109: Vercel Next.js authentication bypass in middleware with Turbopack

CVE-2026-45109 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: Vercel Next.js. Vendors: Vercel.

Executive brief

Next.js is a popular React framework used to build web applications. A previous security fix for middleware-based access controls in App Router applications was incomplete when using Turbopack, allowing attackers to bypass authentication and authorization checks to access protected routes. This affects applications that rely on middleware for authorization and could expose sensitive data to unauthorized users.

Technical details

This vulnerability is a follow-up to CVE-2026-44575 (GHSA-267c-6grr-h53f), an authentication bypass affecting Next.js App Router. The root cause is that middleware matchers do not properly handle transport-specific route variants (.rsc and segment-prefetch URLs) when Turbopack is used as the build tool. An unauthenticated attacker can craft specially crafted requests to these variant routes to bypass authorization checks that would normally apply to the standard page URLs. The vulnerability requires network access but no authentication or user interaction. The fix ensures App Router transport variants are consistently matched by middleware rules. Patches are available in versions 15.5.18 and 16.2.6.

Affected products

  • Vercel Next.js >=15.2.0 <15.5.18, >=16.0.0 <16.2.6

Timeline

  • 2026-05-07: disclosed: Vulnerability publicly disclosed
  • 2026-05-07: patched: Fix released in versions 15.5.18 and 16.2.6

References

Related threats