| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-36qx-fr4f-26g5 | Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 13 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vercel
Vercel next.js |
|
| Vendors & Products |
Vercel
Vercel next.js |
Wed, 13 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intended authorization checks. This vulnerability is fixed in 15.5.16 and 16.2.5. | |
| Title | Next.js: Middleware / Proxy bypass in Pages Router applications using i18n | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-13T18:19:49.658Z
Reserved: 2026-05-06T21:49:12.424Z
Link: CVE-2026-44573
Updated: 2026-05-13T18:11:24.593Z
Status : Awaiting Analysis
Published: 2026-05-13T17:16:22.627
Modified: 2026-05-13T17:25:25.693
Link: CVE-2026-44573
No data.
OpenCVE Enrichment
Updated: 2026-05-13T19:00:15Z
Github GHSA