Bug 2459333 (CVE-2026-40299) - CVE-2026-40299 next-intl: next-intl: Open Redirect vulnerability allows off-site redirection via crafted URLs
Summary: CVE-2026-40299 next-intl: next-intl: Open Redirect vulnerability allows off-s...
Keywords:
Status: NEW
Alias: CVE-2026-40299
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-17 22:01 UTC by OSIDB Bzimport
Modified: 2026-04-20 10:08 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-04-17 22:01:35 UTC
next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-needed'` could construct URLs where path handling and the WHATWG URL parser resolved a relative redirect target to another host (e.g. scheme-relative `//` or control characters stripped by the URL parser), so the middleware could redirect the browser off-site while the user still started from a trusted app URL. The problem has been patchedin `next-intl.1`.


Note You need to log in before you can comment on or make changes to this bug.