VDB
Sign up
HIGH7.5

GHSA-26hh-7cqf-hhc6

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up

Quick fix

GHSA-26hh-7cqf-hhc6 — next: upgrade to the fixed version with the command below.

npm install next@15.5.18

Details

### Impact

It was found that the fix addressing [CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f) did not apply to `middleware.ts` with Turbopack. Refer to [CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f) for further details.

### References

- [CVE CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/next
Introduced in: 15.2.0Fixed in: 15.5.18
Fixnpm install next@15.5.18
npm/next
Introduced in: 16.0.0Fixed in: 16.2.6
Fixnpm install next@16.2.6

References