{"id":"CVE-2026-64646","aliases":["GHSA-4c39-4ccg-62r3"],"title":"Next.js: Unbounded Server Action payload in Edge runtime","summary":"Next.js: Unbounded Server Action payload in Edge runtime","severity":"medium","cwe":["CWE-770"],"vendor":"next","product":"next","ecosystem":"npm","affected":["next >= 13.0.0, < 15.5.21","next >= 16.0.0, < 16.2.11"],"patched":["next 15.5.21","next 16.2.11"],"published":"2026-07-22","updated":"2026-07-22","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-4c39-4ccg-62r3","references":[{"url":"https://github.com/vercel/next.js/security/advisories/GHSA-4c39-4ccg-62r3"},{"url":"https://github.com/vercel/next.js/commit/57c31f724d746e86a9e8b92aa8be538a922446a4"},{"url":"https://github.com/vercel/next.js/commit/9a4651e754f70b12e397694ffc41f44c3ba8cc17"},{"url":"https://github.com/vercel/next.js/releases/tag/v15.5.21"},{"url":"https://github.com/vercel/next.js/releases/tag/v16.2.11"},{"url":"https://github.com/advisories/GHSA-4c39-4ccg-62r3"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-22T23:07:32.194Z","epss":0.00531,"epssPercentile":0.43614,"slug":"CVE-2026-64646","body":"## Overview\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\n## Affected packages\n\n- `next >= 13.0.0, < 15.5.21`\n- `next >= 16.0.0, < 16.2.11`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `next 15.5.21`\n- `next 16.2.11`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}