{"id":"GHSA-7gfc-8cq8-jh5f","summary":"Next.js authorization bypass vulnerability","details":"### Impact\nIf a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed.\n\n### Patches\nThis issue was patched in Next.js `14.2.15` and later.\n\nIf your Next.js application is hosted on Vercel, this vulnerability has been automatically mitigated, regardless of Next.js version.\n\n### Workarounds\nThere are no official workarounds for this vulnerability.\n\n#### Credits\nWe'd like to thank [tyage](http://github.com/tyage) (GMO CyberSecurity by IERAE) for responsible disclosure of this issue.","aliases":["CVE-2024-51479"],"modified":"2025-09-10T21:12:24Z","published":"2024-12-17T15:09:06Z","database_specific":{"github_reviewed_at":"2024-12-17T15:09:06Z","nvd_published_at":"2024-12-17T19:15:06Z","cwe_ids":["CWE-285","CWE-863"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/vercel/next.js/security/advisories/GHSA-7gfc-8cq8-jh5f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-51479"},{"type":"WEB","url":"https://github.com/vercel/next.js/commit/1c8234eb20bc8afd396b89999a00f06b61d72d7b"},{"type":"PACKAGE","url":"https://github.com/vercel/next.js"},{"type":"WEB","url":"https://github.com/vercel/next.js/releases/tag/v14.2.15"}],"affected":[{"package":{"name":"next","ecosystem":"npm","purl":"pkg:npm/next"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.5.5"},{"fixed":"14.2.15"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-7gfc-8cq8-jh5f/GHSA-7gfc-8cq8-jh5f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}