What is CVE-2026-64645?
This vulnerability in Next.js allows `rewrites()` or `redirects()` rules that construct external destination hostnames from request-controlled input to bypass restrictions and point to an arbitrary hostname. It affects versions 12.0.0-15.5.20 and 16.0.0-16.2.10; mitigation requires immediate hostname validation enforcement or a framework update.
Azərbaycanca: Next.js framework-də aşkar edilmiş bu boşluq, xüsusi `rewrites()` və ya `redirects()` qaydaları vasitəsilə istifadəçi tərəfindən idarə olunan sorğu məlumatları ilə xarici host adı təyin edildikdə, təhlükəsizlik məhdudiyyətlərini aşaraq ixtiyari host adına yönləndirməyə imkan verir. 12.0.0-15.5.20 və 16.0.0-16.2.10 versiyalarını təsirləyir; inkişaf etdiricilər dərhal host adı doğrulamasını gücləndirməli və ya çərçivə yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Next.js are affected by CVE-2026-64645?
CVE-2026-64645 affects Next.js versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10.
What should developers do to mitigate CVE-2026-64645?
Developers must immediately enforce hostname validation or apply a framework update.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.