Crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication.
If you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.
{
"cwe_ids": [
"CWE-285"
],
"github_reviewed": true,
"github_reviewed_at": "2026-07-22T22:59:38Z",
"nvd_published_at": null,
"severity": "HIGH"
}