CVE-2026-44572: falha de baixa gravidade em vercel next.js
Next.js: Middleware / Proxy redirects can be cache-poisoned
Publicada em · Atualizada em
8Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 3.7epss 0.2%
probabilidade de exploração
0.2%top 91% das CVEs
exploração observada
nãonenhuma fonte reporta
Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable redirect for normal clients. If the application was deployed behind a CDN or reverse proxy that caches 3xx responses without varying on this header, a single attacker request could poison the cached redirect response for the affected path. Subsequent visitors could then receive a cached redirect response without a Location header, causing a denial of service for that redirect path until the cache entry expired or was purged. This vulnerability is fixed in 15.5.16 and 16.2.5.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Produtos afetados
vercel · next.jsCVEs relacionadas — vercel next.js
No mesmo produto, das mais perigosas para as menos.
CVE-2025-29927CRITICALAuthorization Bypass in Next.js MiddlewareEPSS 99.2%CVE-2024-46982HIGHCache Poisoning in next.jsEPSS 59.2%CVE-2021-43803HIGHUnexpected server crash in Next.jsEPSS 47.3%CVE-2024-34351HIGHNext.js Server-Side Request Forgery in Server ActionsEPSS 5.5%CVE-2024-51479HIGHAuthorization bypass in Next.jsEPSS 4.0%CVE-2025-57822MEDIUMNext.js Improper Middleware Redirect Handling Leads to SSRFEPSS 2.5%