
CVE-2026-40299 next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-needed'` could constr… https://www.cve.org/CVERecord?id=CVE-2026-40299
Post summary
The text reports the existence of CVE-2026-40299, detailing the affected Next.js middleware and configuration, but offers no evidence of exploitation, PoC, or patch.

