Open Redirect Affecting homepage package, versions <1.13.2-r9


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.84% (56th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-HOMEPAGE-18470300
  • published31 Jul 2026
  • disclosed27 Jul 2026

Introduced: 27 Jul 2026

CVE-2026-64645  (opens in a new tab)
CWE-601  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade Chainguard homepage to version 1.13.2-r9 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream homepage package and not the homepage package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A redirects() rule configured this way is vulnerable to an Open Redirect. This issue has been fixed in versions 15.5.21 and 16.2.11.

CVSS Base Scores

version 3.1