next vulnerabilities
CVEs whose affected-version data names the next package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
11 CVEsRSS
GHSA-2xp9-vwfh-vxw4CriticalNext.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
CVE-2026-75604Critical· 9.0PoCNext.js is a React framework for building full-stack web applications
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently esc…
CVE-2026-64648MediumNext.js: Cache confusion of response bodies for requests with bodies
Next.js: Cache confusion of response bodies for requests with bodies
CVE-2026-64649HighNext.js: Server-Side Request Forgery in Server Actions on custom servers
Next.js: Server-Side Request Forgery in Server Actions on custom servers
CVE-2026-64641HighNext.js: Denial of Service in App Router using Server Actions
Next.js: Denial of Service in App Router using Server Actions
CVE-2026-64642HighNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
CVE-2026-64643MediumNext.js: Unauthenticated disclosure of internal Server Function endpoints
Next.js: Unauthenticated disclosure of internal Server Function endpoints
CVE-2026-64644MediumNext.js: Denial of Service in the Image Optimization API using SVGs
Next.js: Denial of Service in the Image Optimization API using SVGs
CVE-2026-64645HighNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
CVE-2026-64646MediumNext.js: Unbounded Server Action payload in Edge runtime
Next.js: Unbounded Server Action payload in Edge runtime
CVE-2026-64647MediumNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences