Bug 2477207 (CVE-2026-44574) - CVE-2026-44574 Next.js: Next.js: Authorization bypass via crafted query parameters
Summary: CVE-2026-44574 Next.js: Next.js: Authorization bypass via crafted query param...
Keywords:
Status: NEW
Alias: CVE-2026-44574
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2484241 2484254 2484255 2484231 2484238 2484244 2484256
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-13 18:02 UTC by OSIDB Bzimport
Modified: 2026-07-05 07:38 UTC (History)
16 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:34608 0 None None None 2026-07-02 00:04:48 UTC

Description OSIDB Bzimport 2026-05-13 18:02:43 UTC
Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 15.5.16 and 16.2.5.

Comment 2 errata-xmlrpc 2026-07-02 00:04:47 UTC
This issue has been addressed in the following products:

  Streams for Apache Kafka 2.9.4

Via RHSA-2026:34608 https://access.redhat.com/errata/RHSA-2026:34608


Note You need to log in before you can comment on or make changes to this bug.