Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Published May 13, 2026
7.5
HIGHCVSS 3.1
EPSS 0.76%
Description
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to be reached without the expected authorization check. This vulnerability is fixed in 15.5.16 and 16.2.5.
Affected products
-
- Version >= 15.2.0, < 15.5.16StatusaffectedConstraints-
- Version >= 16.0.0, < 16.2.5StatusaffectedConstraints-
- Version
No data.
Red Hat Trusted Artifact Signer 1.3
rhtas/rekor-search-ui-rhel9:1783958622
Fixed · RHSA-2026:40974
Red Hat Trusted Artifact Signer 1.4
rhtas/rekor-search-ui-rhel9:1783327185
Fixed · RHSA-2026:37272
Streams for Apache Kafka 2.9.4
next
Fixed · RHSA-2026:34608
Streams for Apache Kafka 3.2.1
next
Fixed · RHSA-2026:54435
Red Hat Enterprise Linux 10
firefox
Not affected
Red Hat Enterprise Linux 10
thunderbird
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 8
thunderbird
Not affected
Red Hat Enterprise Linux 9
firefox
Not affected
Red Hat Enterprise Linux 9
thunderbird
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Trusted Artifact Signer 1.3 | rhtas/rekor-search-ui-rhel9:1783958622 | Fixed | RHSA-2026:40974 |
| Red Hat Trusted Artifact Signer 1.4 | rhtas/rekor-search-ui-rhel9:1783327185 | Fixed | RHSA-2026:37272 |
| Streams for Apache Kafka 2.9.4 | next | Fixed | RHSA-2026:34608 |
| Streams for Apache Kafka 3.2.1 | next | Fixed | RHSA-2026:54435 |
| Red Hat Enterprise Linux 10 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 10 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Will not fix | n/a |
next
npm
Introduced 15.2.0 Fixed 15.5.16next
npm
Introduced 16.0.0 Fixed 16.2.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | next | 15.2.0 | 15.5.16 |
| npm | next | 16.0.0 | 16.2.5 |
Remediation
Red Hat statement
This is an Important flaw in Next.js App Router applications that utilize middleware or proxy-based authorization. A remote attacker can bypass these security checks by crafting specific URLs, leading to unauthorized access to protected content. This is due to transport-specific route variants used for segment prefetching not being consistently matched by middleware rules.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed May 13, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.76% (0.00761) | 53.67th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.05% (0.01048) | 59.63th | v5 (v2026.06.15) |
| May 14, 2026 | 0.03% (0.00029) | 8.42th | v4 (v2025.03.14) |
References (13)
- https://access.redhat.com/errata/RHSA-2026:34608
- https://access.redhat.com/errata/RHSA-2026:37272
- https://access.redhat.com/errata/RHSA-2026:40974
- https://access.redhat.com/errata/RHSA-2026:54435
- https://access.redhat.com/security/cve/CVE-2026-44575 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2477188 Issue Tracking
- https://github.com/advisories/GHSA-267c-6grr-h53f Advisory
- https://github.com/vercel/next.js/releases/tag/v15.5.16
- https://github.com/vercel/next.js/releases/tag/v16.2.5
- https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-44575
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44575.json
- https://www.cve.org/CVERecord?id=CVE-2026-44575
Change history (0)
No recorded changes yet.