CVE-2024-51479: Authorization bypass in Next.js

Published Dec 17, 2024
·
Updated

Impact If a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed.

Patches This issue was patched in Next.js 14.2.15 and later.

If your Next.js application is hosted on Vercel, this vulnerability has been automatically mitigated, regardless of Next.js version.

Workarounds There are no official workarounds for this vulnerability.

Credits We'd like to thank tyage (GMO CyberSecurity by IERAE) for responsible disclosure of this issue.

Other sources

Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root directory. For example: [Not affected] https://example.com/ [Affected] https://example.com/foo [Not affected] https://example.com/foo/bar. This issue is patched in Next.js 14.2.15 and later. If your Next.js application is hosted on Vercel, this vulnerability has been automatically mitigated, regardless of Next.js version. There are no official workarounds for this vulnerability.

MITRE

Affected Software

2 affected componentsFixes available
npm/next>=9.5.5<14.2.15
14.2.15
Vercel Next.js Node.js>=9.5.5<14.2.15

Event History

Dec 17, 2024
Advisory Published
via GitHub·03:09 PM
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
Affected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-51479?

The severity of CVE-2024-51479 is considered to be high due to the potential for authorization bypass in Next.js applications.

2

How do I fix CVE-2024-51479?

To fix CVE-2024-51479, upgrade your Next.js application to version 14.2.15 or later.

3

Who is affected by CVE-2024-51479?

CVE-2024-51479 affects Next.js applications using authorization based on pathname prior to version 14.2.15.

4

What will happen if I don't patch CVE-2024-51479?

If you don't patch CVE-2024-51479, your Next.js application may be vulnerable to authorization bypass attacks.

5

Is this vulnerability specific to Next.js hosted on Vercel?

CVE-2024-51479 is not limited to Vercel; it affects any Next.js application using the vulnerable authorization method.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203