CVE-2026-64645
## Impact A `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect. This affects any destination that puts a dynamic segment in the hostname, whether from the path: ```javascript // next.config.js module.exports = { async rewrites() { return [ { source: '/:tenant', destination: 'https://:tenant.api.example.com', }, ] }, } ``` or from a `has` capture: ```javascript // next.config.js module.exports = { async rewrites() { return [ { source: '/', has: [{ type: 'query', key: 'region', value: '(?<region>.+)' }], destination: 'https://:region.api.example.com', }, ] }, } ``` ## Workarounds If you cannot upgrade immediately, do not build the hostname of an external `rewrites()` or `redirects()` destination from user-controlled input. If a dynamic subdomain is required, constrain the value to hostname-safe characters: `value: '(?<region>[a-z0-9-]+)'`.
Properties
- ghsa_id
- GHSA-p9j2-gv94-2wf4
- summary
- Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
- severity
- high
- epss_score
- 0.00837
- cve_id
- CVE-2026-64645
- is_ghsa_only
- false
- ghsa_published
- 2026-07-22T23:02:23Z
- source_url
- https://github.com/advisories/GHSA-p9j2-gv94-2wf4
- epss_percentile
- 0.54984
- ghsa_updated
- 2026-07-22T23:02:25Z
Related Entities (5)
ENRICHED_BY (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph