PT-2026-39754 · Vercel · Next.Js+1

·

CVE-2026-45109

·

Published

2026-05-11

·

Updated

2026-08-17

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Next.js versions 15.2.0 through 15.5.17 Next.js versions 16.0.0 through 16.2.5
Description A flaw exists where a previous security fix was not correctly applied to middleware.ts when used in conjunction with Turbopack, a high-performance incremental bundler for JavaScript and TypeScript.
Recommendations Update to version 15.5.18. Update to version 16.2.6.

Exploit

Fix

Improperly Implemented Security Check for Standard

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07875
CVE-2026-45109
GHSA-26HH-7CQF-HHC6

Affected Products

Next.Js
Turbopack