CVE-2026-29057 is an HTTP request smuggling vulnerability in Next.js rewrites that proxy requests to external backends. It affects releases starting with 9.5.0, before the fixes in 15.5.13 and 16.1.7. A crafted DELETE or OPTIONS request using Transfer-Encoding: chunked can cause the Next.js proxy and backend to disagree about request boundaries, allowing an additional request to reach unintended backend routes. The flaw originates in a vendored upstream library's handling of Content-Length and Transfer-Encoding headers. Applications hosted on providers that handle rewrites at the CDN level, such as Vercel, are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This 20-file repository is a self-contained educational Docker lab for CVE-2026-29057, a request-smuggling/request-desynchronization issue in Next.js external rewrites. It builds identical Next.js applications with versions 15.5.12 (vulnerable) and 15.5.13 (patched), exposing them on localhost ports 3105 and 3106 respectively. The core exploit runner, scripts/run-cve-2026-29057.mjs, uses Node.js raw TCP rather than fetch so HTTP framing is preserved. It submits a chunked DELETE request to the rewritten workspace route, with an embedded GET /secret in its body, then checks /api/state for downstream evidence. The lab topology is implemented in support/server.js: Next.js on port 3000 rewrites traffic to an intermediary on 127.0.0.1:4000, which forwards it to a backend on 127.0.0.1:5000. The backend records every parsed request in /tmp/cve-2026-29057-state.json and sets a fixed demonstration flag when /secret is reached. next.config.js supplies the external rewrite. App routes provide reset/state evidence APIs and an intentionally leaked operations manifest; robots.txt points to that manifest to support the lab's route-discovery narrative. The remaining materials are presentation, runbook, and contract-test documentation. The repository contains an actual, hard-coded operational PoC for its isolated local topology, not merely a detector; its payload demonstrates access to a simulated backend-only route rather than arbitrary command execution.
Repository is a multi-PoC lab for three Next.js vulnerabilities, not a single offensive implant or framework module. Structure is cleanly split into pocs/ for vulnerable demo apps and scripts/ for reproduction drivers, with docker-compose.yml orchestrating vulnerable and fixed side-by-side containers. Languages are primarily JavaScript/Node.js with Docker and YAML support files. CVE-2025-29927 PoC: a minimal Next.js app protects /dashboard only via middleware in pocs/cve-2025-29927/middleware.js. The exploit script scripts/run-cve-2025-29927.mjs sends a normal request and then a second request with attacker-controlled x-middleware-subrequest set to repeated middleware names. On vulnerable versions, this causes middleware recursion-depth logic to be treated as already exhausted, skipping middleware execution and exposing the protected dashboard. Capability: authorization bypass. CVE-2026-27978 PoC: the app in pocs/cve-2026-27978 exposes a Server Action transferFunds that records a transfer if a session cookie exists. The helper endpoints /api/login, /api/reset, and /api/state support setup and observation. The exploit script scripts/run-cve-2026-27978.mjs obtains a victim session cookie from /api/login, fetches the page to parse the generated $ACTION_* field, then submits the form with Cookie plus Origin: null. On vulnerable versions, the Server Action executes and mutates state. Capability: CSRF-style state-changing action execution under a victim session. CVE-2026-29057 PoC: the app in pocs/cve-2026-29057 rewrites /rewrites/* to an external intermediary at http://127.0.0.1:4000. support/server.js launches three components: Next.js on port 3000, an intermediary proxy on 4000, and a backend on 5000 that records requests into /tmp/cve-2026-29057-state.json. The exploit script scripts/run-cve-2026-29057.mjs uses raw TCP via node:net to send a crafted chunked DELETE /rewrites/poc containing a smuggled GET /secret. On vulnerable versions, both requests are observed by the backend. Capability: HTTP request smuggling through rewrite/proxy behavior. Overall purpose: provide reproducible, side-by-side vulnerable/fixed environments to validate and study three Next.js security issues. The repository is a legitimate proof-of-concept suite with active exploit logic, not merely documentation or passive detection.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.