Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40299

Опубликовано: 17 апр. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

next-intl provides internationalization for Next.js. Applications using the next-intl middleware prior to version 4.9.1with localePrefix: 'as-needed' could construct URLs where path handling and the WHATWG URL parser resolved a relative redirect target to another host (e.g. scheme-relative // or control characters stripped by the URL parser), so the middleware could redirect the browser off-site while the user still started from a trusted app URL. The problem has been patchedin next-intl@4.9.1.

A flaw was found in next-intl, a library for internationalization in Next.js applications. A remote attacker could exploit this vulnerability in applications using the next-intl middleware with localePrefix: 'as-needed'. By crafting specific URLs, the attacker could cause the middleware to redirect a user's browser to an arbitrary external website, even if the user initially started from a trusted application URL. This could lead to users being unknowingly directed to malicious sites.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
streams for Apache Kafka 2com.github.streamshub-consoleNot affected
streams for Apache Kafka 2next-intlOut of support scope
streams for Apache Kafka 3com.github.streamshub-consoleNot affected
streams for Apache Kafka 3next-intlFix deferred
streams for Apache Kafka 3next-intl-swc-plugin-extractorFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2459333next-intl: next-intl: Open Redirect vulnerability allows off-site redirection via crafted URLs

EPSS

Процентиль: 26%
0.00339
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

nvd
4 месяца назад

next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-needed'` could construct URLs where path handling and the WHATWG URL parser resolved a relative redirect target to another host (e.g. scheme-relative `//` or control characters stripped by the URL parser), so the middleware could redirect the browser off-site while the user still started from a trusted app URL. The problem has been patchedin `next-intl@4.9.1`.

github
4 месяца назад

next-intl has an open redirect vulnerability

EPSS

Процентиль: 26%
0.00339
Низкий

4.3 Medium

CVSS3