CVE-2026-29057General(vercel / next.js)

MEDIUMCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vercel next.js systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, internal/admin endpoints), bypassing assumptions that only the configured rewrite destination/path is reachable. This does not impact applications hosted on providers that handle rewrites at the CDN level, such as Vercel. The vulnerability originated in an upstream library vendored by Next.js. It is fixed in Next.js 15.5.13 and 16.1.7 by updating that dependency’s behavior so `content-length: 0` is added only when both `content-length` and `transfer-encoding` are absent, and `transfer-encoding` is no longer removed in that code path. If upgrading is not immediately possible, block chunked `DELETE`/`OPTIONS` requests on rewritten routes at the edge/proxy, and/or enforce authentication/authorization on backend routes.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-27); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-03-17: 1Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Mentions · 2026-03-27: 2Mentions · 2026-09-21: 1Mentions · 2026-09-22: 1PoC Mentioned / Linked · 2026-09-21: 1PoC Mentioned / Linked · 2026-09-22: 1Exploit Tool / Code · 2026-09-21: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-09-22: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-27: 1Technical Details · 2026-09-21: 1Technical Details · 2026-09-22: 103-1703-1803-1903-2709-2109-22
Signal classification5 categories
General
342.9%
Patch
114.3%
Disclosure
114.3%
Exploit
114.3%
PoC
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-171
Patch1
2026-03-181
General1
2026-03-191
General1
2026-03-272
Disclosure1General1
2026-09-211
Exploit1
2026-09-221
PoC1
Full discourse7 posts
  • HeroDevs@herodevs
    Disclosure

    🚨 Two new CVEs impacting Next.js — What happens after support ends? CVE-2026-29057 and CVE-2026-27980 highlight a familiar pattern: → Request handling weaknesses that introduce unexpected behavior → Resource management issues that can impact application stability Both affect multiple versions of Next.js and for many teams those versions are already end-of-life. That’s the real risk → When a framework reaches EOL, fixes don’t follow. No patches. No updates. Just exposure. You can keep moving forward, but the threats don’t stop chasing. 👾 This is where teams get stuck: Migration takes time. Risk doesn’t wait. HeroDevs Never-Ending Support (NES) provides patched, drop-in replacements for EOL versions, so you can stay secure while planning your upgrade. Because the vulnerability isn’t just the CVE. It’s the software that will never be fixed. #NextJS #CVE #AppSec #OpenSourceSecurity #EOL #DevSecOps #HeroDevs

    Post summary

    Two new CVEs affecting EOL versions of Next.js raise stability risks, and HeroDevs offers patched replacements to help teams mitigate while upgrading.

    10000184
    2.7K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Next.js'teki CVE-2026-29057 HTTP Request Smuggling / Request Desynchronization açığı için PoC yayınlandı. PoC, 15.5.12 (etkilenen) ve 15.5.13 (yamalanmış) sürümlerini karşılaştırarak tek HTTP isteği üzerinden ikinci bir isteğin backend'e sızdırılabildiğini gösteriyor. https://github.com/learnerxuan/CVE-2026-29057-POC

    Post summary

    A PoC for CVE-2026-29057 (HTTP Request Smuggling in Next.js) has been published on GitHub, demonstrating the issue between affected version 15.5.12 and patched version 15.5.13.

    00000205
    2.4K followersView on X
  • cybrmonk@cybr_monk
    Exploit

    CVE-2026-29057 Lets Attackers Smuggle Requests Through Next.js Rewrites, Exploit Code Is Live https://cybrmonk.com/blog/cve-2026-29057-lets-attackers-smuggle-requests-through-next-js-rewrites-exploit-code-is-live #cybersecurity #threatintelligence https://t.co/XH4oTrJkJP

    Post summary

    The text announces CVE-2026-29057, a request smuggling vulnerability in Next.js rewrites, with exploit code confirmed live. No patch or active exploitation in the wild is mentioned.

    0000036
    45 followersView on X
  • HeroDevs@herodevs
    General

    Learn more 🔗 https://www.herodevs.com/blog-posts/cve-2026-29057-and-cve-2026-27980-two-new-vulnerabilities-affecting-end-of-life-next-js

    Post summary

    The text merely references two CVEs via a link, without providing details on exploitation, patches, or vulnerability specifics.

    0000086
    2.7K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-29057 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-29057 #CVE-2026-29057 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/iBfsoHkENY

    Post summary

    The tweet merely announces CVE‑2026-29057 with a severity score and a link to NVD, providing no technical insights, PoC, exploitation, or mitigation details.

    0000031
    104 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-29057 Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy… https://www.cve.org/CVERecord?id=CVE-2026-29057

    Post summary

    The post announces CVE‑2026‑29057, noting the affected Next.js versions and a proxy rewrite issue, but provides no info on exploitation, patches, or PoC.

    00000117
    56.7K followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Next.js v15.5.13 がリリースされました。 📦 種別: patch 🔧 重要な修正: • リライトにおけるリクエストスマグリングを防ぐため、http-proxyをパッチ適用 (CVE-2026-29057) #GitHub #Release #Next.js

    Post summary

    Next.js v15.5.13 has been released as a patch to fix CVE-2026-29057, addressing request smuggling via http‑proxy; no PoC, exploit code, or active exploitation is referenced.

    0000048
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more