← Back to CVE List
CVE-2026-64645NVD
Vulnerability Summary
## Impact
A `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.
This affects any destination that puts a dynamic segment in the hostname, whether from the path:
```javascript
// next.config.js
module.exports = {
async rewrites() {
return [
{
source: '/:tenant',
destination: 'https://:tenant.api.example.com',
},
]
},
}
```
or from a `has` capture:
```javascript
// next.config.js
module.exports = {
async rewrites() {
return [
{
source: '/',
has: [{ type: 'query', key: 'region', value: '(?<region>.+)' }],
destination: 'https://:region.api.example.com',
},
]
},
}
```
## Workarounds
If you cannot upgrade immediately, do not build the hostname of an external `rewrites()` or `redirects()` destination from user-controlled input. If a dynamic subdomain is required, constrain the value to hostname-safe characters: `value: '(?<region>[a-z0-9-]+)'`.
A `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.
This affects any destination that puts a dynamic segment in the hostname, whether from the path:
```javascript
// next.config.js
module.exports = {
async rewrites() {
return [
{
source: '/:tenant',
destination: 'https://:tenant.api.example.com',
},
]
},
}
```
or from a `has` capture:
```javascript
// next.config.js
module.exports = {
async rewrites() {
return [
{
source: '/',
has: [{ type: 'query', key: 'region', value: '(?<region>.+)' }],
destination: 'https://:region.api.example.com',
},
]
},
}
```
## Workarounds
If you cannot upgrade immediately, do not build the hostname of an external `rewrites()` or `redirects()` destination from user-controlled input. If a dynamic subdomain is required, constrain the value to hostname-safe characters: `value: '(?<region>[a-z0-9-]+)'`.