CVE-2026-44574: Next.js: Middleware / Proxy bypass through dynamic route parameter injection

Published May 11, 2026
·
Updated

Impact

Applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check.

Fix

We now only honor internal route-parameter normalization in trusted routing flows and ignore externally supplied parameter encodings that should never have been accepted from ordinary requests.

Workarounds

If you cannot upgrade immediately, enforce authorization in route or page logic instead of relying solely on middleware path matching.

Other sources

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 15.5.16 and 16.2.5.

MITRE

Affected Software

4 affected componentsFixes available
npm/next>=16.0.0<16.2.5
16.2.5
npm/next>=15.4.0<15.5.16
15.5.16
Vercel Next.js Node.js>=15.4.0<15.5.16
Vercel Next.js Node.js>=16.0.0<16.2.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/next to a version that resolves this vulnerability.

    Fixed in 16.2.5
  2. Upgrade

    Upgrade npm/next to a version that resolves this vulnerability.

    Fixed in 15.5.16
  3. Upgrade

    Upgrade Next.js to a version that resolves this vulnerability.

    Fixed in 15.5.16
  4. Upgrade

    Upgrade Next.js to a version that resolves this vulnerability.

    Fixed in 16.2.5
  5. Configuration

    If you cannot upgrade immediately, enforce authorization in route or page logic instead of relying solely on middleware path matching; additionally ensure externally supplied parameter encodings that could inject/alter dynamic route parameters are ignored while only internal normalization is honored in trusted routing flows.

    Next.js middleware/proxy route handling Route-parameter normalization trust boundary = Only honor internal route-parameter normalization in trusted routing flows; ignore externally supplied parameter encodings from ordinary requests

Event History

May 11, 2026
Advisory Published
via GitHub·03:54 PM
Data Sourced
via GitHub·03:54 PM
DescriptionSeverityWeaknessAffected Software
May 13, 2026
CVE Published
via MITRE·04:56 PM
Data Sourced
via MITRE·04:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·06:02 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-44574?

CVE-2026-44574 has been classified with a critical severity due to its potential to allow unauthorized access.

2

How do I fix CVE-2026-44574?

To mitigate CVE-2026-44574, upgrade to Next.js version 16.2.5 or 15.5.16.

3

What applications are affected by CVE-2026-44574?

CVE-2026-44574 affects Next.js applications that utilize middleware for dynamic route protection.

4

What type of vulnerability is CVE-2026-44574?

CVE-2026-44574 is an authorization bypass vulnerability that can be exploited through dynamic route parameter injection.

5

Who is the vendor associated with CVE-2026-44574?

The vendor associated with CVE-2026-44574 is Vercel, the company behind Next.js.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203