Open Redirect Affecting next-intl package, versions <4.9.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Open Redirect vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-NEXTINTL-15995498
  • published12 Apr 2026
  • disclosed10 Apr 2026
  • creditjoniumGit

Introduced: 10 Apr 2026

New CVE NOT AVAILABLE CWE-601  (opens in a new tab)

How to fix?

Upgrade next-intl to version 4.9.1 or higher.

Overview

next-intl is an Internationalization (i18n) for Next.js

Affected versions of this package are vulnerable to Open Redirect in the middleware process when localePrefix is set to 'as-needed'. An attacker can redirect users to an external site by crafting URLs that exploit the way relative redirect targets are resolved and handled by the URL parser.

CVSS Base Scores

version 4.0
version 3.1