CVE-2026-44578
Next.js May 2026 coordinated security release (13 advisories): SSRF via the middleware/proxy request path, plus middleware and proxy bypass CVE-2026-44573, cache poisoning on middleware redirects CVE-2026-44572 and image-optimizer DoS CVE-2026-44577
- Severity
- high
- Affected product
- Next.js
- Affected versions
- Next.js ≥ 16.0.0, < 16.2.6
- Affected versions
- Next.js ≥ 15.0.0, < 15.5.18
- Fixed in
- Next.js 16.2.6
- Fixed in
- Next.js 15.5.18
- Added to NewScan
- 2026-07-30
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Next.js from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-05 (docs/api-breach-review-2026.md, Vercel/Next.js case set). One row per supported branch covering the whole 2026-05-06 release, the way the Bouncy Castle row covers eleven CVEs fixed by one upgrade: 15.5.18 or 16.2.6 closes the set. Self-hosted deployments carry all of it; Vercel-hosted apps are unaffected by the image DoS and the cache-poisoning issue because the platform handles middleware and image optimization.
COMPONENT VERSION RANGE
NewScan fingerprints Next.js from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-05 (docs/api-breach-review-2026.md, Vercel/Next.js case set). One row per supported branch covering the whole 2026-05-06 release, the way the Bouncy Castle row covers eleven CVEs fixed by one upgrade: 15.5.18 or 16.2.6 closes the set. Self-hosted deployments carry all of it; Vercel-hosted apps are unaffected by the image DoS and the cache-poisoning issue because the platform handles middleware and image optimization.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →