{"id":"GHSA-6gpp-xcg3-4w24","summary":"Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale","details":"## Impact\n\nCrafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.\n\n## Workarounds\n\nIf you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.","aliases":["CVE-2026-64642"],"modified":"2026-07-22T23:25:40.305781Z","published":"2026-07-22T22:59:38Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-22T22:59:38Z","nvd_published_at":null,"cwe_ids":["CWE-285"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/vercel/next.js/security/advisories/GHSA-6gpp-xcg3-4w24"},{"type":"WEB","url":"https://github.com/vercel/next.js/pull/96014"},{"type":"WEB","url":"https://github.com/vercel/next.js/commit/6bf4df14508ad6c0cd46af50c6051ee42f2d9151"},{"type":"PACKAGE","url":"https://github.com/vercel/next.js"},{"type":"WEB","url":"https://github.com/vercel/next.js/releases/tag/v16.2.11"}],"affected":[{"package":{"name":"next","ecosystem":"npm","purl":"pkg:npm/next"},"ranges":[{"type":"SEMVER","events":[{"introduced":"16.0.0"},{"fixed":"16.2.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6gpp-xcg3-4w24/GHSA-6gpp-xcg3-4w24.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}]}