System running
Last check: 2026-09-29 01:26:15 | Auto-updates every hour
756 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-CVE-2026-29057

Severity
MEDIUM
CVSS Score
6.5
Description

Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, interna...

PoCs for CVE-CVE-2026-29057

CVE-2026-29057-POC
General JavaScript 0
learnerxuan 2026-09-21
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources