PT-2026-39754 · Vercel · Turbopack+1

Tim Neutkens

·

Published

2026-05-11

·

Updated

2026-05-15

·

CVE-2026-45109

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Next.js versions 15.2.0 through 15.5.17 Next.js versions 16.0.0 through 16.2.5
Description A flaw exists where a previous security fix was not correctly applied to middleware.ts when used in conjunction with Turbopack, a high-performance incremental bundler for JavaScript and TypeScript.
Recommendations Update to version 15.5.18. Update to version 16.2.6.

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2026-45109
GHSA-26HH-7CQF-HHC6

Affected Products

Next.Js
Turbopack