VDB
Sign up
CRITICAL9.1

GHSA-f82v-jwr5-mffw

Authorization Bypass in Next.js Middleware

Quick fix

GHSA-f82v-jwr5-mffw — next: upgrade to the fixed version with the command below.

npm install next@13.5.9

Details

# Impact It is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware.

# Patches * For Next.js 15.x, this issue is fixed in `15.2.3` * For Next.js 14.x, this issue is fixed in `14.2.25` * For Next.js 13.x, this issue is fixed in 13.5.9 * For Next.js 12.x, this issue is fixed in 12.3.5 * For Next.js 11.x, consult the below workaround.

_Note: Next.js deployments hosted on Vercel are automatically protected against this vulnerability._

# Workaround If patching to a safe version is infeasible, we recommend that you prevent external user requests which contain the `x-middleware-subrequest` header from reaching your Next.js application.

## Credits

- Allam Rachid (zhero;) - Allam Yasser (inzo_)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/next
Introduced in: 13.0.0Fixed in: 13.5.9
Fixnpm install next@13.5.9
npm/next
Introduced in: 14.0.0Fixed in: 14.2.25
Fixnpm install next@14.2.25
npm/next
Introduced in: 15.0.0Fixed in: 15.2.3
Fixnpm install next@15.2.3
npm/next
Introduced in: 12.0.0Fixed in: 12.3.5
Fixnpm install next@12.3.5

References