Executive brief
Next.js is a popular framework used to build and deploy web applications. A security flaw in certain configurations allows attackers to bypass authentication checks performed by middleware or proxies. This could lead to unauthorized access to sensitive data or restricted areas of the application.
Technical details
An improper authorization vulnerability (CWE-285) exists in Next.js versions 16.0.0 through 16.2.10. The issue occurs when an application uses the App Router built with Turbopack and has exactly one entry in the 'config.i18n.locales' configuration. In this specific environment, the Turbopack middleware matcher fails to correctly process certain crafted requests, allowing them to bypass middleware-level security checks or proxy-based authentication. Attackers can exploit this over the network without prior authentication to access restricted routes. The vulnerability is resolved in version 16.2.11 by correcting the middleware matching logic in the Turbopack implementation.
Affected products
- Vercel Next.js >= 16.0.0, < 16.2.11
Timeline
- 2026-07-21: patched: Fixed in version 16.2.11
- 2026-07-21: advisory: GitHub Security Advisory GHSA-6gpp-xcg3-4w24 published
- 2026-07-27: disclosed: CVE-2026-64642 published to NVD