next is vulnerable to Authorization Bypass
83
High Risk
Next.js applications using the App Router built with Turbopack and a single entry in config.i18n.locales mishandle path normalization for locale-prefixed routes. A crafted request can reach a protected route in a form that middleware does not match, so middleware- or proxy-based authentication checks are skipped. This lets an unauthenticated caller bypass authorization and access protected pages. The fix corrects locale route handling so middleware runs for the affected requests.
You are affected if you are using a version that falls within the vulnerable range and your application uses the App Router built with Turbopack and a single entry in config.i18n.locales.
next is vulnerable to Authorization Bypass in versions 16.0.0 - 16.2.10.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant