High severity8.2OSV Advisory· Published Jul 27, 2026· Updated Jul 29, 2026
CVE-2026-64642
CVE-2026-64642
Description
Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has been fixed in version 16.2.11.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nextnpm | >= 16.0.0, < 16.2.11 | 16.2.11 |
Affected products
11- osv-coords8 versionspkg:apk/chainguard/homepagepkg:apk/chainguard/langfuse-fips-3-workerpkg:apk/wolfi/langfuse-3pkg:apk/chainguard/langfuse-3pkg:apk/wolfi/langfuse-3-workerpkg:apk/chainguard/langfuse-3-workerpkg:apk/chainguard/langfuse-fips-3pkg:apk/chainguard/peerdb-ui
< 1.13.2-r9+ 7 more
- (no CPE)range: < 1.13.2-r9
- (no CPE)range: < 3.224.1-r0
- (no CPE)range: < 3.224.1-r0
- (no CPE)range: < 3.224.1-r0
- (no CPE)range: < 3.224.1-r0
- (no CPE)range: < 3.224.1-r0
- (no CPE)range: < 3.224.1-r0
- (no CPE)range: < 0.37.3-r1
Patches
Vulnerability mechanics
References
5- github.com/vercel/next.js/commit/6bf4df14508ad6c0cd46af50c6051ee42f2d9151nvdPatchWEB
- github.com/vercel/next.js/pull/96014nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-6gpp-xcg3-4w24ghsaADVISORY
- github.com/vercel/next.js/security/advisories/GHSA-6gpp-xcg3-4w24nvdVendor AdvisoryWEB
- github.com/vercel/next.js/releases/tag/v16.2.11nvdProductRelease NotesWEB
News mentions
4- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026
- Next.js: Nine SSRF, Auth Bypass, and DoS Vulnerabilities Patched TogetherVypr Intelligence · Jul 27, 2026
- Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 StoriesCyber Security News · Jul 26, 2026
- Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS AttacksCyber Security News · Jul 23, 2026