{"id":"CVE-2026-64645","aliases":["GHSA-p9j2-gv94-2wf4"],"title":"Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname","summary":"Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname","severity":"high","cwe":["CWE-918"],"vendor":"next","product":"next","ecosystem":"npm","affected":["next >= 12.0.0, < 15.5.21","next >= 16.0.0, < 16.2.11"],"patched":["next 15.5.21","next 16.2.11"],"published":"2026-07-22","updated":"2026-07-22","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-p9j2-gv94-2wf4","references":[{"url":"https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4"},{"url":"https://github.com/vercel/next.js/commit/35f501357e9b0fe7c950b0d6aa8fcf5343f707e9"},{"url":"https://github.com/vercel/next.js/commit/d3033266c6dff23f7be71e19341fe3a8c6e2c599"},{"url":"https://github.com/vercel/next.js/releases/tag/v15.5.21"},{"url":"https://github.com/vercel/next.js/releases/tag/v16.2.11"},{"url":"https://github.com/advisories/GHSA-p9j2-gv94-2wf4"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-22T23:07:32.217Z","epss":0.00837,"epssPercentile":0.55781,"slug":"CVE-2026-64645","body":"## Overview\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segment in the hostname, whether from the path:\n\n```javascript\n// next.config.js\nmodule.exports = {\n  async rewrites() {\n    return [\n      {\n        source: '/:tenant',\n        destination: 'https://:tenant.api.example.com',\n      },\n    ]\n  },\n}\n```\n\nor from a `has` capture:\n\n```javascript\n// next.config.js\nmodule.exports = {\n  async rewrites() {\n    return [\n      {\n        source: '/',\n        has: [{ type: 'query', key: 'region', value: '(?<region>.+)' }],\n        destination: 'https://:region.api.example.com',\n      },\n    ]\n  },\n}\n```\n\n## Workarounds\n\nIf you cannot upgrade immediately, do not build the hostname of an external `rewrites()` or `redirects()` destination from user-controlled input. If a dynamic subdomain is required, constrain the value to hostname-safe characters:  `value: '(?<region>[a-z0-9-]+)'`.\n\n## Affected packages\n\n- `next >= 12.0.0, < 15.5.21`\n- `next >= 16.0.0, < 16.2.11`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `next 15.5.21`\n- `next 16.2.11`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}