highVulnerability

CVE-2026-64642

## Impact Crafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication. ## Workarounds If you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.

Properties

ghsa_id
GHSA-6gpp-xcg3-4w24
summary
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
severity
high
epss_score
0.01009
cve_id
CVE-2026-64642
is_ghsa_only
false
ghsa_published
2026-07-22T22:59:38Z
source_url
https://github.com/advisories/GHSA-6gpp-xcg3-4w24
epss_percentile
0.60322
ghsa_updated
2026-07-22T22:59:39Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/next

AFFECTS (1)

[Software]npm/next

HAS_WEAKNESS (1)

[Weakness]Improper Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-64642 — Ninja Signal Threat Intelligence | Ninja Signal