目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-44572— Next.js 安全漏洞

CVSS 3.7 · Low EPSS 0.28% · P21

Affected Version Matrix 2

ベンダープロダクトVersion Rangeステータス
vercelnext.js>= 12.2.0, < 15.5.16affected
>= 16.0.0, < 16.2.5affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-44572の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Next.js: Middleware / Proxy redirects can be cache-poisoned
ソース: CVE Program / CVE List V5
脆弱性説明
Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable redirect for normal clients. If the application was deployed behind a CDN or reverse proxy that caches 3xx responses without varying on this header, a single attacker request could poison the cached redirect response for the affected path. Subsequent visitors could then receive a cached redirect response without a Location header, causing a denial of service for that redirect path until the cache entry expired or was purged. This vulnerability is fixed in 15.5.16 and 16.2.5.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
ソース: CVE Program / CVE List V5
脆弱性タイプ
在可信数据中接受外来的不可信数据
ソース: CVE Program / CVE List V5
脆弱性タイトル
Next.js 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Next.js是Vercel开源的一个 React 框架。 Next.js 12.2.0至15.5.16之前版本和16.2.5之前版本存在安全漏洞,该漏洞源于外部客户端可在由返回重定向的中间件处理的正常请求上发送x-nextjs-data标头,可能导致后续访问者收到无Location标头的缓存重定向响应,造成拒绝服务。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
vercelnext.js >= 12.2.0, < 15.5.16 -

II. CVE-2026-44572の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-44572のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-44572 厂商安全公告 (1)

Same Patch Batch · vercel · 2026-05-13 · 13 CVEs total

CVE-2026-445788.6 HIGHNext.js: Server-side request forgery in applications using WebSocket upgrades
CVE-2026-445748.1 HIGHNext.js: Middleware / Proxy bypass through dynamic route parameter injection
CVE-2026-451097.5 HIGHNext.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVE-2026-445797.5 HIGHNext.js: Denial of Service via connection exhaustion in applications using Cache Component
CVE-2026-445757.5 HIGHNext.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVE-2026-445737.5 HIGHNext.js: Middleware / Proxy bypass in Pages Router applications using i18n
CVE-2026-445806.1 MEDIUMNext.js: Cross-site scripting in beforeInteractive scripts with untrusted input
CVE-2026-445775.9 MEDIUMNext.js: Denial of Service in the Image Optimization API
CVE-2026-444795.5 MEDIUMVercel: Non-interactive mode includes CLI arguments in suggested command output
CVE-2026-445765.4 MEDIUMNext.js: Cache poisoning in React Server Component responses
CVE-2026-445814.7 MEDIUMNext.js: Cross-site scripting in App Router applications using CSP nonces
CVE-2026-445823.7 LOWNext.js: Cache poisoning via collisions in React Server Component cache-busting

IV. 関連脆弱性

V. CVE-2026-44572へのコメント

まだコメントはありません


コメントを残す