securityonline.info 7/23/2026, 4:32:30 PM · external

Next.js patches three critical SSRF and auth bypass bugs fixed

Next.js patches three critical SSRF and auth bypass bugs fixed
CyberSIXT Evidence Panel

THE page reports on critical vulnerabilities detected in Next.js. Specifically, three issues (CVE-2026-64645, CVE-2026-64649, CVE-2026-64642) were fixed in versions 16.2.11 and 15.5.21, all rated CVSS 8.3. These vulnerabilities include: 1) Server-Side Request Forgery (SSRF) due to insecure rewrite rules; 2) similar SSRF risks in Server Actions; and 3) a middleware authentication bypass. Affected versions span from 12.0.0 to 16.2.10. Users are urged to upgrade to the patched versions and take precautionary measures. No current exploitation has been confirmed in the wild.

View Primary Source Via securityonline.info

Article by CyberSIXT