OVERVIEW: CVE-2026-40299 is a URL redirection vulnerability in the next-intl library, an internationalization middleware for Next.js applications. The flaw exists in versions prior to 4.9.1 when configured with the "localePrefix: 'as-needed'" setting. The vulnerability allows attackers to craft malicious URLs that exploit path handling and WHATWG URL parser behavior to redirect users to arbitrary external hosts while maintaining the appearance of a legitimate application URL, potentially facilitating phishing or credential theft attacks. SEVERITY: The vulnerability has a FAUCET Risk Score of 36.0/100, indicating moderate risk. While exact CVSS metrics are unavailable, the attack requires user interaction (clicking a crafted link) and relies on specific application configuration, reducing immediate threat severity. The attack exploits the URL parser's handling of scheme-relative paths (double slashes) and control characters that are stripped during parsing, enabling off-site redirection from an initially trusted domain. EXPLOITATION STATUS: The vulnerability demonstrates minimal active exploitation risk. It is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and has an extremely low EPSS score of 0.0005, indicating negligible probability of exploitation in the wild. No public exploit code appears readily available, and community attention remains limited. Organizations should prioritize patching to version 4.9.1 or later, but this does not represent an immediate critical threat requiring emergency response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Amannn | Next-Intl | < 4.9.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.