๐Ÿ” CVE Alert

CVE-2026-64642

UNKNOWN 0.0

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has been fixed in version 16.2.11.

CWE CWE-285
Vendor vercel
Product next.js
Published Jul 27, 2026
Stay Ahead of the Next One

Get instant alerts for vercel next.js

Be the first to know when new unknown vulnerabilities affecting vercel next.js are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

vercel / next.js
>= 16.0.0, < 16.2.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/vercel/next.js/security/advisories/GHSA-6gpp-xcg3-4w24 github.com: https://github.com/vercel/next.js/pull/96014 github.com: https://github.com/vercel/next.js/commit/6bf4df14508ad6c0cd46af50c6051ee42f2d9151 github.com: https://github.com/vercel/next.js/releases/tag/v16.2.11