CVE-2026-8890: Next Middleware Unvalidated Header Bypass

Returning NextResponse.next() solely based on the presence of an HTTP header without validating its value can lead to authentication or authorization bypass. In middleware, this may allow malicious clients to bypass checks and spoof downstream identities. Verify the header value against a known secret or perform token validation before proceeding, and strip

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-8890-next-middleware-unvalidated-header-bypass --engine opengrep

Description

Returning NextResponse.next() solely based on the presence of an HTTP header without validating its value can lead to authentication or authorization bypass. In middleware, this may allow malicious clients to bypass checks and spoof downstream identities. Verify the header value against a known secret or perform token validation before proceeding, and strip