Feed/CVE-2026-64642
CVE-2026-64642HIGHCVSS 8.2

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

Published Jul 22, 2026·Updated Jul 29, 2026

NVD Description

## Impact Crafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication. ## Workarounds If you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.

Affected Packages (1)

nextNPM
From 16.0.0
Fixed in 16.2.11

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free