Next.js: Middleware / Proxy bypass through dynamic route parameter injection
Published May 13, 2026
8.1
HIGHCVSS 3.1
EPSS 0.67%
Description
Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 15.5.16 and 16.2.5.
Affected products
-
- Version >= 15.4.0, < 15.5.16StatusaffectedConstraints-
- Version >= 16.0.0, < 16.2.5StatusaffectedConstraints-
- Version
No data.
Red Hat Trusted Artifact Signer 1.3
rhtas/rekor-search-ui-rhel9:1783958622
Fixed · RHSA-2026:40974
Red Hat Trusted Artifact Signer 1.4
rhtas/rekor-search-ui-rhel9:1783327185
Fixed · RHSA-2026:37272
Streams for Apache Kafka 2.9.4
next
Fixed · RHSA-2026:34608
Streams for Apache Kafka 3.2.1
next
Fixed · RHSA-2026:54435
Red Hat Enterprise Linux 10
firefox
Not affected
Red Hat Enterprise Linux 10
thunderbird
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 8
thunderbird
Not affected
Red Hat Enterprise Linux 9
firefox
Not affected
Red Hat Enterprise Linux 9
thunderbird
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Trusted Artifact Signer 1.3 | rhtas/rekor-search-ui-rhel9:1783958622 | Fixed | RHSA-2026:40974 |
| Red Hat Trusted Artifact Signer 1.4 | rhtas/rekor-search-ui-rhel9:1783327185 | Fixed | RHSA-2026:37272 |
| Streams for Apache Kafka 2.9.4 | next | Fixed | RHSA-2026:34608 |
| Streams for Apache Kafka 3.2.1 | next | Fixed | RHSA-2026:54435 |
| Red Hat Enterprise Linux 10 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 10 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Will not fix | n/a |
next
npm
Introduced 15.4.0 Fixed 15.5.16next
npm
Introduced 16.0.0 Fixed 16.2.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | next | 15.4.0 | 15.5.16 |
| npm | next | 16.0.0 | 16.2.5 |
Remediation
Red Hat statement
This is an Important authorization bypass flaw in Next.js applications, which are utilized in Red Hat AMQ, Red Hat Trusted Artifact Signer, and Red Hat Enterprise Linux AI. The vulnerability arises when applications use Next.js middleware to protect dynamic routes, allowing attackers to access restricted content by manipulating query parameters. This bypass occurs because specially crafted parameters can alter the route value seen by the page while the visible path remains unchanged, circumventing intended security controls.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (13)
- https://access.redhat.com/errata/RHSA-2026:34608
- https://access.redhat.com/errata/RHSA-2026:37272
- https://access.redhat.com/errata/RHSA-2026:40974
- https://access.redhat.com/errata/RHSA-2026:54435
- https://access.redhat.com/security/cve/CVE-2026-44574 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2477207 Issue Tracking
- https://github.com/advisories/GHSA-492v-c6pp-mqqv Advisory
- https://github.com/vercel/next.js/releases/tag/v15.5.16
- https://github.com/vercel/next.js/releases/tag/v16.2.5
- https://github.com/vercel/next.js/security/advisories/GHSA-492v-c6pp-mqqv x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-44574
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44574.json
- https://www.cve.org/CVERecord?id=CVE-2026-44574
Change history (0)
No recorded changes yet.