CVE-2026-29057: HTTP request smuggling via Next.js rewrites
Next.js disclosed CVE-2026-29057 (CVSS 6.3): a bug in the bundled http-proxy deleteLength() function strips Transfer-Encoding on proxied DELETE and OPTIONS requests while still forwarding the body. An attacker can smuggle a second request inside the body and reach internal routes. Affected versions are 9.5.0–15.5.13 and 16.0.0-beta.0–16.1.7; fixes ship in 15.5.13 and 16.1.7.
- Affected: Next.js >= 9.5.0, < 15.5.13 and >= 16.0.0-beta.0, < 16.1.7
- Patched in versions 15.5.13 and 16.1.7
- CVSS 4.0 score 6.3, CWE-444 request smuggling
- Impacts self-hosted deployments using rewrites() to proxy to a backend
Read next
Security