← All CVEs NewScan detects
high

CVE-2026-44578

Next.js May 2026 coordinated security release (13 advisories): SSRF via the middleware/proxy request path, plus middleware and proxy bypass CVE-2026-44573, cache poisoning on middleware redirects CVE-2026-44572 and image-optimizer DoS CVE-2026-44577

Severity
high
Affected product
Next.js
Affected versions
Next.js ≥ 16.0.0, < 16.2.6
Affected versions
Next.js ≥ 15.0.0, < 15.5.18
Fixed in
Next.js 16.2.6
Fixed in
Next.js 15.5.18
Added to NewScan
2026-07-30
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Next.js from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-05 (docs/api-breach-review-2026.md, Vercel/Next.js case set). One row per supported branch covering the whole 2026-05-06 release, the way the Bouncy Castle row covers eleven CVEs fixed by one upgrade: 15.5.18 or 16.2.6 closes the set. Self-hosted deployments carry all of it; Vercel-hosted apps are unaffected by the image DoS and the cache-poisoning issue because the platform handles middleware and image optimization.

COMPONENT VERSION RANGE

NewScan fingerprints Next.js from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-05 (docs/api-breach-review-2026.md, Vercel/Next.js case set). One row per supported branch covering the whole 2026-05-06 release, the way the Bouncy Castle row covers eleven CVEs fixed by one upgrade: 15.5.18 or 16.2.6 closes the set. Self-hosted deployments carry all of it; Vercel-hosted apps are unaffected by the image DoS and the cache-poisoning issue because the platform handles middleware and image optimization.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →