next is vulnerable to Authentication Bypass
81
High Risk
Dynamic route handling can accept externally supplied parameter encodings that alter route values seen by page logic. Middleware checks may evaluate a different effective route than the rendered target. This mismatch can bypass expected authorization enforcement on protected paths. The fix limits parameter normalization to trusted internal routing flows.
You are affected if you are using a version that falls within the vulnerable range.
next is vulnerable to Authentication Bypass in versions 15.4.0 - 15.5.15 and 16.0.0 - 16.2.4.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant