CVE-2026-8890: Next Middleware Unvalidated Header Bypass
Returning NextResponse.next() solely based on the presence of an HTTP header without validating its value can lead to authentication or authorization bypass. In middleware, this may allow malicious clients to bypass checks and spoof downstream identities. Verify the header value against a known secret or perform token validation before proceeding, and strip
greprules fetch cve-2026-8890-next-middleware-unvalidated-header-bypass --engine opengrepDescription
Returning NextResponse.next() solely based on the presence of an HTTP header without validating its value can lead to authentication or authorization bypass. In middleware, this may allow malicious clients to bypass checks and spoof downstream identities. Verify the header value against a known secret or perform token validation before proceeding, and strip
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.