Bug 2507617 (CVE-2026-64642)

Summary: CVE-2026-64642 next: Next.js: Authentication bypass leading to unauthorized access
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aazores, abrianik, akostadi, amasferr, amctagga, ant, anujha, aoconnor, aschwart, asoldano, aszczucz, ataylor, avibelli, bbaranow, bbrownin, bgeorges, bmaxwell, bniver, boliveir, bstansbe, cescoffi, chfoley, cmah, dandread, dbruscin, dkreling, dlofthou, dmayorov, drichtar, eaguilar, ebaron, eborisov, ehugonne, ewittman, flucifre, fmariani, fmongiar, ggrzybek, gmalinko, gmeno, gotiwari, groman, gsmet, istudens, ivassile, iweiss, janstey, jhorak, jlledo, jmartisk, jmatsuok, jnethert, jraez, jtolenti, jwon, kaycoth, kvanderr, lball, lthon, manderse, mbenjamin, mcarlett, mhackett, mosmerov, mposolda, msvehla, mvyas, ngough, nipatil, nwallace, olubyans, pantinor, parichar, pberan, pesilva, pgallagh, pjindal, pmackay, probinso, rgodfrey, rguimara, rhel-process-autobot, rkubis, rmartinc, rruss, rstancel, rstepani, rsvoboda, sbiarozk, sostapov, ssilvert, sthorger, swoodman, tasato, tcunning, thjenkin, tqvarnst, tsedmik, vdosoudi, vereddy, veshanka, vmuzikar, watson-tool-maintainers, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Next.js, a React framework. A remote attacker can bypass authentication in Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales by sending crafted requests. This vulnerability allows for unauthorized access, leading to a high impact on confidentiality through information disclosure.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-07-27 19:02:31 UTC
Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has been fixed in version 16.2.11.