chiprook
← Security
SecurityOctober 5, 2026, 08:28

CVE-2026-29057: HTTP request smuggling via Next.js rewrites

Next.js disclosed CVE-2026-29057 (CVSS 6.3): a bug in the bundled http-proxy deleteLength() function strips Transfer-Encoding on proxied DELETE and OPTIONS requests while still forwarding the body. An attacker can smuggle a second request inside the body and reach internal routes. Affected versions are 9.5.0–15.5.13 and 16.0.0-beta.0–16.1.7; fixes ship in 15.5.13 and 16.1.7.

CVE-2026-29057: HTTP request smuggling via Next.js rewrites
#Next.js
Read next
Security

CVE-2026-84411 in MikroTik RouterOS: unauthenticated HTTP request reaches root

Security

CISA: Request Smuggling in Starlette and LiteLLM Exploited

Security

Critical request smuggling flaw found in Citrix NetScaler

Security

CVE-2026-94545: Critical SVG Injection in Vercel Satori and Next.js ImageResponse