Posted inCloudflare WAF
WAF – WAF Release – 2026-05-07 – Emergency
This emergency release introduces a new rule to detect Next.js App Router middleware and proxy bypass attempts via segment-prefetch routes (CVE-2026-44575). Key Findings CVE-2026-44575: Next.js Middleware / Proxy Bypass in App Router Applications via Segment-Prefetch Routes Successful exploitation allows unauthenticated…





