tag
NxtP-Injection
CVE-2026-44574
web
HIGH 8.1
Next.js Dynamic Route Injection Auth Bypass (CVE-2026-44574)
CVE-2026-44574 is an authentication bypass in Next.js App Router applications that use middleware to protect dynamic route pages. Specially crafted query parameters (nxtP / nxtI internal Next.js route params) injected on a public URL cause the App Router…
Patched
2026-05-17