What is CVE-2026-64642?
The identified CVE-2026-64642 vulnerability in the Next.js framework allows bypassing middleware or proxy-based authentication via crafted requests. This affects applications from version 16.0.0 to 16.2.10 that use the App Router with Turbopack and a single entry in config.i18n.locales. Updating to the latest version is recommended to mitigate the issue.
Azərbaycanca: Next.js framework-ində müəyyən edilmiş CVE-2026-64642 zəifliyi, xüsusi hazırlanmış sorğular vasitəsilə middleware və ya proxy əsaslı autentifikasiyanın yan keçilməsinə imkan verir. Bu, 16.0.0-dan 16.2.10-a qədər versiyalarda, App Router ilə Turbopack istifadə edən və config.i18n.locales-də tək girişi olan tətbiqlərə təsir göstərir. Təhlükəsizliyi təmin etmək üçün framework-ü ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of Next.js are affected by the CVE-2026-64642 vulnerability?
The vulnerability affects versions from 16.0.0 to 16.2.10.
What should I do to protect against the CVE-2026-64642 vulnerability?
It is recommended to update the Next.js framework to the latest version to ensure security.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.