Wiz Agents & Workflows are here

CVE-2026-29057
ASP.NET Core vulnerability analysis and mitigation

Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted DELETE/OPTIONS request using Transfer-Encoding: chunked could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, internal/admin endpoints), bypassing assumptions that only the configured rewrite destination/path is reachable. This does not impact applications hosted on providers that handle rewrites at the CDN level, such as Vercel. The vulnerability originated in an upstream library vendored by Next.js. It is fixed in Next.js 15.5.13 and 16.1.7 by updating that dependency’s behavior so content-length: 0 is added only when both content-length and transfer-encoding are absent, and transfer-encoding is no longer removed in that code path. If upgrading is not immediately possible, block chunked DELETE/OPTIONS requests on rewritten routes at the edge/proxy, and/or enforce authentication/authorization on backend routes.


SourceNVD

Related ASP.NET Core vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-27980MEDIUM6.9
  • ASP.NET CoreASP.NET Core
  • dotnet-targeting-pack-7.0
NoYesMar 18, 2026
CVE-2026-27979MEDIUM6.9
  • ASP.NET CoreASP.NET Core
  • dotnet-targeting-pack-7.0
NoYesMar 18, 2026
CVE-2026-29057MEDIUM6.3
  • ASP.NET CoreASP.NET Core
  • dotnet-templates-7.0
NoYesMar 18, 2026
CVE-2026-27978MEDIUM5.3
  • ASP.NET CoreASP.NET Core
  • aspnetcore-targeting-pack-7.0
NoYesMar 18, 2026
CVE-2026-27977LOW2.3
  • ASP.NET CoreASP.NET Core
  • dotnet7.0
NoYesMar 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management