---
id: CVE-2026-44575
title: Next.js is a React framework for building full-stack web applications
summary: >-
  Next.js is a React framework for building full-stack web applications. From
  15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on
  middleware or proxy-based checks for authorization can allow unauthorized
  access throug…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-288
  - CWE-551
vendor: vercel
product: next.js
affected:
  - 'next.js >= 15.2.0, < 15.5.16'
  - 'next.js >= 16.0.0, < 16.2.5'
patched:
  - next.js 16.2.5
published: '2026-05-13'
updated: '2026-07-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44575'
references:
  - url: 'https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f'
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:34608'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-44575'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2477188'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44575.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.01594
epssPercentile: 0.74218
ingestedAt: '2026-07-03T14:03:37.051Z'
---

## Overview

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to be reached without the expected authorization check. This vulnerability is fixed in 15.5.16 and 16.2.5.

## Affected

- `next.js >= 15.2.0, < 15.5.16`
- `next.js >= 16.0.0, < 16.2.5`

## Remediation

Upgrade past the affected range:

- `next.js 16.2.5`
