CVE-2026-45109High· 7.5▾ TwilightNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fix…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
0.5% → 0.6%
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.
next.js >= 15.2.0, < 15.5.18next.js >= 16.0.0, < 16.2.6Upgrade past the affected range:
next.js 16.2.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44575High· 7.5Next.js is a React framework for building full-stack web applications
CVE-2026-44574High· 8.1Next.js is a React framework for building full-stack web applications
CVE-2026-44579High· 7.5Next.js is a React framework for building full-stack web applications
CVE-2026-44578High· 8.6Next.js is a React framework for building full-stack web applications
CVE-2026-44577Medium· 5.9Next.js is a React framework for building full-stack web applications
CVE-2026-44573High· 7.5Next.js is a React framework for building full-stack web applications