VulnSea

next has 11 CVEs on record. Disclosure cadence is accelerating: 11 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 9. The median CVSS is 9.0 (critical), with 2 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.0
Publish → KEV
Last 90 days
11 prev 0

Products

  • next 11
11
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

next vulnerabilities

CVEs affecting next, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

GHSA-2xp9-vwfh-vxw4Critical
2w ago

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

Midnightnext · nextvia GHSA
CVE-2026-75604Critical· 9.0PoC
3w ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently esc…

Abyssalnext · nextEPSS 2.5%via NVD
CVE-2026-64648Medium
2mo ago

Next.js: Cache confusion of response bodies for requests with bodies

Next.js: Cache confusion of response bodies for requests with bodies

Sunlitnext · nextEPSS 0.34%via GHSA
CVE-2026-64649High
2mo ago

Next.js: Server-Side Request Forgery in Server Actions on custom servers

Next.js: Server-Side Request Forgery in Server Actions on custom servers

Twilightnext · nextEPSS 0.87%via GHSA
CVE-2026-64641High
2mo ago

Next.js: Denial of Service in App Router using Server Actions

Next.js: Denial of Service in App Router using Server Actions

Twilightnext · nextEPSS 1.4%via GHSA
CVE-2026-64642High
2mo ago

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

Twilightnext · nextEPSS 1.2%via GHSA
CVE-2026-64643Medium
2mo ago

Next.js: Unauthenticated disclosure of internal Server Function endpoints

Next.js: Unauthenticated disclosure of internal Server Function endpoints

Sunlitnext · nextEPSS 0.52%via GHSA
CVE-2026-64644Medium
2mo ago

Next.js: Denial of Service in the Image Optimization API using SVGs

Next.js: Denial of Service in the Image Optimization API using SVGs

Sunlitnext · nextEPSS 0.68%via GHSA
CVE-2026-64645High
2mo ago

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

Twilightnext · nextEPSS 0.84%via GHSA
CVE-2026-64646Medium
2mo ago

Next.js: Unbounded Server Action payload in Edge runtime

Next.js: Unbounded Server Action payload in Edge runtime

Sunlitnext · nextEPSS 0.53%via GHSA
CVE-2026-64647Medium
2mo ago

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

Sunlitnext · nextEPSS 0.35%via GHSA
next vulnerabilities (CVEs) · VulnSea