CVE-2026-44573High· 7.5▾ TwilightNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized acc…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
0.6% → 0.6%
Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intended authorization checks. This vulnerability is fixed in 15.5.16 and 16.2.5.
next.js >= 12.2.0, < 15.5.16next.js >= 16.0.0, < 16.2.5Upgrade past the affected range:
next.js 16.2.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44575High· 7.5Next.js is a React framework for building full-stack web applications
CVE-2026-44574High· 8.1Next.js is a React framework for building full-stack web applications
CVE-2026-50559High· 7.5Quarkus is a Java framework for building cloud-native applications
CVE-2026-45109High· 7.5Next.js is a React framework for building full-stack web applications
CVE-2026-44579High· 7.5Next.js is a React framework for building full-stack web applications
CVE-2026-44578High· 8.6Next.js is a React framework for building full-stack web applications