Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40299

23
FAUCET Score

OVERVIEW: CVE-2026-40299 is a URL redirection vulnerability in the next-intl library, an internationalization middleware for Next.js applications. The flaw exists in versions prior to 4.9.1 when configured with the "localePrefix: 'as-needed'" setting. The vulnerability allows attackers to craft malicious URLs that exploit path handling and WHATWG URL parser behavior to redirect users to arbitrary external hosts while maintaining the appearance of a legitimate application URL, potentially facilitating phishing or credential theft attacks. SEVERITY: The vulnerability has a FAUCET Risk Score of 36.0/100, indicating moderate risk. While exact CVSS metrics are unavailable, the attack requires user interaction (clicking a crafted link) and relies on specific application configuration, reducing immediate threat severity. The attack exploits the URL parser's handling of scheme-relative paths (double slashes) and control characters that are stripped during parsing, enabling off-site redirection from an initially trusted domain. EXPLOITATION STATUS: The vulnerability demonstrates minimal active exploitation risk. It is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and has an extremely low EPSS score of 0.0005, indicating negligible probability of exploitation in the wild. No public exploit code appears readily available, and community attention remains limited. Organizations should prioritize patching to version 4.9.1 or later, but this does not represent an immediate critical threat requiring emergency response.

Impacted Technologies

VendorProductVersion(s)CPE
AmannnNext-Intl
< 4.9.1CNA affected

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 16th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

npmpatch availablevia ghsa
Product: next-intlFixed in: 4.9.1

Vendor Advisories (1)

npmGHSA-8f24-v5vv-gm5jmedium

next-intl has an open redirect vulnerability

Apr 10, 2026

References

github.com / amannn/next-intl/commit/1c80b668aa6d853f470319eec10a3f61e78a70e6
github.com / amannn/next-intl/pull/2304
github.com / amannn/next-intl/releases/tag/v4.9.1
github.com / amannn/next-intl/security/advisories/GHSA-8f24-v5vv-gm5j