PT-2026-32979 · Npm · Next-Intl

Published

2026-04-10

·

Updated

2026-04-18

·

CVE-2026-40299

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions next-intl versions prior to 4.9.1
Description Applications using the middleware with localePrefix: 'as-needed' could construct URLs where path handling and the WHATWG URL parser resolved a relative redirect target to another host. This occurs through mechanisms such as scheme-relative // or control characters stripped by the URL parser, allowing the middleware to redirect the browser off-site from a trusted application URL.
Recommendations Update to version 4.9.1.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2026-40299
GHSA-8F24-V5VV-GM5J

Affected Products

Next-Intl