Cross-site scripting in Next.js - CVE-2026-44580
Published: May 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in a visitor's browser.
The vulnerability exists due to improper neutralization of input during web page generation in beforeInteractive script content serialization when embedding untrusted content into the document. A remote attacker can supply specially crafted input to execute arbitrary JavaScript in a visitor's browser.
User interaction is required to load the affected page.
Affected software
Event Processing
Maximo Application Suite - Monitor Component
How to mitigate CVE-2026-44580
Event Processing - update to 1.5.5
Maximo Application Suite - Monitor Component - addressed in versions 9.0.22, 9.1.12