{"ghsa_id":"GHSA-26hh-7cqf-hhc6","cve_id":"CVE-2026-45109","url":"https://api.github.com/advisories/GHSA-26hh-7cqf-hhc6","html_url":"https://github.com/advisories/GHSA-26hh-7cqf-hhc6","summary":"Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up","description":"### Impact\n\n\nIt was found that the fix addressing [CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f) did not apply to `middleware.ts` with Turbopack. Refer to  [CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f) for further details.\n\n### References \n\n- [CVE CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f)","type":"reviewed","severity":"high","repository_advisory_url":"https://api.github.com/repos/vercel/next.js/security-advisories/GHSA-26hh-7cqf-hhc6","source_code_location":"https://github.com/vercel/next.js","identifiers":[{"value":"GHSA-26hh-7cqf-hhc6","type":"GHSA"},{"value":"CVE-2026-45109","type":"CVE"}],"references":["https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f","https://github.com/vercel/next.js/security/advisories/GHSA-26hh-7cqf-hhc6","https://github.com/vercel/next.js/releases/tag/v15.5.18","https://github.com/vercel/next.js/releases/tag/v16.2.6","https://nvd.nist.gov/vuln/detail/CVE-2026-45109","https://github.com/advisories/GHSA-26hh-7cqf-hhc6"],"published_at":"2026-05-11T16:21:19Z","updated_at":"2026-05-14T20:39:05Z","github_reviewed_at":"2026-05-11T16:21:19Z","nvd_published_at":"2026-05-13T18:16:19Z","withdrawn_at":null,"vulnerabilities":[{"package":{"ecosystem":"npm","name":"next"},"vulnerable_version_range":">= 15.2.0, < 15.5.18","first_patched_version":"15.5.18","vulnerable_functions":[]},{"package":{"ecosystem":"npm","name":"next"},"vulnerable_version_range":">= 16.0.0, < 16.2.6","first_patched_version":"16.2.6","vulnerable_functions":[]}],"cvss_severities":{"cvss_v3":{"vector_string":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","score":7.5},"cvss_v4":{"vector_string":null,"score":0.0}},"cwes":[{"cwe_id":"CWE-288","name":"Authentication Bypass Using an Alternate Path or Channel"}],"credits":[],"cvss":{"vector_string":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","score":7.5},"epss":{"percentage":0.00569,"percentile":0.44632}}