CVE-2026-56682

CVE-2026-56682 published: 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, checkLock, and recor...

View full NVD advisory → ← Back to CVE watch