CVE-2026-45109: Vercel Next.js

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.

Affected products

  • Vercel Next.js: from 15.2.0, before 15.5.18 (fixed in 15.5.18); from 16.0.0, before 16.2.6 (fixed in 16.2.6)

Published 2026-05-13. Last modified 2026-08-13.