Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-64642

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

A flaw was found in Next.js, a React framework. A remote attacker can bypass authentication in Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales by sending crafted requests. This vulnerability allows for unauthorized access, leading to a high impact on confidentiality through information disclosure.

Отчет

Important: A flaw in Next.js applications, when specifically configured with App Router, Turbopack, and a single internationalization locale entry, allows for authentication bypass. This could enable unauthorized access to web applications utilizing such a configuration within Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxAffected
Red Hat Enterprise Linux 10thunderbirdAffected
Red Hat Enterprise Linux 7firefoxAffected
Red Hat Enterprise Linux 8firefoxAffected
Red Hat Enterprise Linux 8thunderbirdAffected
Red Hat Enterprise Linux 9firefoxAffected
Red Hat Enterprise Linux 9thunderbirdAffected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gaudi-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-807
https://bugzilla.redhat.com/show_bug.cgi?id=2507617next: Next.js: Authentication bypass leading to unauthorized access

EPSS

Процентиль: 58%
0.00948
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
5 дней назад

Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has been fixed in version 16.2.11.

github
10 дней назад

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

EPSS

Процентиль: 58%
0.00948
Низкий

8.2 High

CVSS3