PoC Archive PoC Archive

tag

NxtP-Injection

  • CVE-2026-44574 web HIGH 8.1

    Next.js Dynamic Route Injection Auth Bypass (CVE-2026-44574)

    CVE-2026-44574 is an authentication bypass in Next.js App Router applications that use middleware to protect dynamic route pages. Specially crafted query parameters (nxtP / nxtI internal Next.js route params) injected on a public URL cause the App Router…

    Patched 2026-05-17