Skip to content

Open redirect vulnerability

Moderate
amannn published GHSA-8f24-v5vv-gm5j Apr 10, 2026

Package

npm next-intl (npm)

Affected versions

<4.9.1

Patched versions

4.9.1

Description

Impact

Applications using the next-intl middleware with localePrefix: 'as-needed' could construct URLs where path handling and the WHATWG URL parser resolved a relative redirect target to another host (e.g. scheme-relative // or control characters stripped by the URL parser), so the middleware could redirect the browser off-site while the user still started from a trusted app URL.

Patches

The problem has been patched, please update to next-intl@4.9.1.

Credits

Many thanks to Joni Liljeblad from Oura for responsibly disclosing the vulnerability and for suggesting the fix.

Severity

Moderate

CVE ID

CVE-2026-40299

Weaknesses

No CWEs

Credits