HIGH7.5
GHSA-26hh-7cqf-hhc6
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
Quick fix
GHSA-26hh-7cqf-hhc6 — next: upgrade to the fixed version with the command below.
npm install next@15.5.18Details
### Impact
It was found that the fix addressing [CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f) did not apply to `middleware.ts` with Turbopack. Refer to [CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f) for further details.
### References
- [CVE CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f[WEB]
- https://github.com/vercel/next.js/security/advisories/GHSA-26hh-7cqf-hhc6[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-45109[ADVISORY]
- https://github.com/vercel/next.js[PACKAGE]
- https://github.com/vercel/next.js/releases/tag/v15.5.18[WEB]
- https://github.com/vercel/next.js/releases/tag/v16.2.6[WEB]