{"ghsa_id":"GHSA-267c-6grr-h53f","cve_id":"CVE-2026-44575","url":"https://api.github.com/advisories/GHSA-267c-6grr-h53f","html_url":"https://github.com/advisories/GHSA-267c-6grr-h53f","summary":"Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes","description":"### Impact\n\nApp Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted `.rsc` and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to be reached without the expected authorization check.\n\n### Fix\n\nWe now include App Router transport variants when generating middleware matchers, so middleware protections are applied consistently to those requests as well as to the normal page URL.\n\n### Workarounds\n\nIf you cannot upgrade immediately, enforce authorization in the underlying route or page logic instead of relying solely on middleware.","type":"reviewed","severity":"high","repository_advisory_url":"https://api.github.com/repos/vercel/next.js/security-advisories/GHSA-267c-6grr-h53f","source_code_location":"https://github.com/vercel/next.js","identifiers":[{"value":"GHSA-267c-6grr-h53f","type":"GHSA"},{"value":"CVE-2026-44575","type":"CVE"}],"references":["https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f","https://github.com/vercel/next.js/releases/tag/v15.5.16","https://github.com/vercel/next.js/releases/tag/v16.2.5","https://nvd.nist.gov/vuln/detail/CVE-2026-44575","https://github.com/advisories/GHSA-267c-6grr-h53f"],"published_at":"2026-05-11T15:54:24Z","updated_at":"2026-05-14T20:38:09Z","github_reviewed_at":"2026-05-11T15:54:24Z","nvd_published_at":"2026-05-13T17:16:22Z","withdrawn_at":null,"vulnerabilities":[{"package":{"ecosystem":"npm","name":"next"},"vulnerable_version_range":">= 15.2.0, < 15.5.16","first_patched_version":"15.5.16","vulnerable_functions":[]},{"package":{"ecosystem":"npm","name":"next"},"vulnerable_version_range":">= 16.0.0, < 16.2.5","first_patched_version":"16.2.5","vulnerable_functions":[]}],"cvss_severities":{"cvss_v3":{"vector_string":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","score":7.5},"cvss_v4":{"vector_string":null,"score":0.0}},"cwes":[{"cwe_id":"CWE-288","name":"Authentication Bypass Using an Alternate Path or Channel"}],"credits":[],"cvss":{"vector_string":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","score":7.5},"epss":{"percentage":0.01594,"percentile":0.73815}}