VendorsVercelnext.jsall versions
Vulnerabilities

Vercel Next.js

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Published 2025-12-03 · Analyzed
10.0KEV1 PoCEPSS 0.998
CVE-2025-29927
Authorization Bypass in Next.js Middleware
Published 2025-03-21 · Analyzed
9.11 PoCEPSS 0.992
CVE-2026-44578
Next.js: Server-side request forgery in applications using WebSocket upgrades
Published 2026-05-13 · Modified
8.6EPSS 0.019
CVE-2026-64642
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
Published 2026-07-27 · Analyzed
8.3EPSS 0.006
CVE-2026-64649
Next.js: Server-Side Request Forgery in Server Actions on Custom Servers
Published 2026-07-27 · Analyzed
8.3EPSS 0.005
CVE-2026-64645
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
Published 2026-07-27 · Analyzed
8.3EPSS 0.004
CVE-2025-57822
Next.js Improper Middleware Redirect Handling Leads to SSRF
Published 2025-08-29 · Analyzed
8.2EPSS 0.025
CVE-2026-64641
Next.js: Denial of Service in App Router using Server Actions
Published 2026-07-27 · Analyzed
8.2EPSS 0.009
CVE-2026-44574
Next.js: Middleware / Proxy bypass through dynamic route parameter injection
Published 2026-05-13 · Modified
8.1EPSS 0.007
CVE-2025-55184
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
Published 2025-12-11 · Modified
7.5EPSS 0.669
CVE-2024-46982
Cache Poisoning in next.js
Published 2024-09-17 · Analyzed
7.5EPSS 0.592
CVE-2021-43803
Unexpected server crash in Next.js
Published 2021-12-09 · Modified
7.5EPSS 0.448
CVE-2025-67779
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
Published 2025-12-11 · Modified
7.5EPSS 0.200
CVE-2024-34351
Next.js Server-Side Request Forgery in Server Actions
Published 2024-05-09 · Analyzed
7.5EPSS 0.055
CVE-2024-51479
Authorization bypass in Next.js
Published 2024-12-17 · Analyzed
7.5EPSS 0.040
CVE-2022-21721
DOS Vulnerability in next.js
Published 2022-01-28 · Modified
7.5EPSS 0.022
CVE-2022-23646
Improper CSP in Image Optimization API for Next.js
Published 2022-02-17 · Modified
7.5EPSS 0.018
CVE-2023-46298
Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.
Published 2023-10-22 · Modified
7.5EPSS 0.013
CVE-2024-34350
Next.js Vulnerable to HTTP Request Smuggling
Published 2024-05-09 · Analyzed
7.5EPSS 0.012
CVE-2021-39178
XSS in Image Optimization API for Next.js versions between 10.0.0 and 11.1.0
Published 2021-08-30 · Modified
7.5EPSS 0.011
CVE-2025-49826
Next.js DoS vulnerability via cache poisoning
Published 2025-07-03 · Analyzed
7.5EPSS 0.011
CVE-2026-44577
Next.js: Denial of Service in the Image Optimization API
Published 2026-05-13 · Modified
7.5EPSS 0.009
CVE-2026-27980
Next.js: Unbounded next/image disk cache growth can exhaust storage
Published 2026-03-18 · Analyzed
7.5EPSS 0.008
CVE-2026-27979
Next.js: Unbounded postponed resume buffering can lead to DoS
Published 2026-03-18 · Analyzed
7.5EPSS 0.008
CVE-2026-44579
Next.js: Denial of Service via connection exhaustion in applications using Cache Components
Published 2026-05-13 · Modified
7.5EPSS 0.008
CVE-2026-44573
Next.js: Middleware / Proxy bypass in Pages Router applications using i18n
Published 2026-05-13 · Modified
7.5EPSS 0.008
CVE-2026-44575
Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Published 2026-05-13 · Modified
7.5EPSS 0.008
CVE-2026-45109
Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Published 2026-05-13 · Modified
7.5EPSS 0.008
CVE-2024-47831
Next.js image optimization has Denial of Service condition
Published 2024-10-14 · Analyzed
7.5EPSS 0.007
CVE-2025-59471
A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and that the attacker can serve or control a large image on an allowed domain. Strongly consider upgrading to 15.5.10 or 16.1.5 to reduce risk and prevent availability issues in Next applications.
Published 2026-01-26 · Analyzed
7.5EPSS 0.005
CVE-2024-39693
Next.js Denial of Service (DoS) condition
Published 2024-07-10 · Analyzed
7.5EPSS 0.005
CVE-2025-59472
A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-controlled postponed state data. Two closely related vulnerabilities allow an attacker to crash the server process through memory exhaustion: 1. **Unbounded request body buffering**: The server buffers the entire POST request body into memory using `Buffer.concat()` without enforcing any size limit, allowing arbitrarily large payloads to exhaust available memory. 2. **Unbounded decompression (zipbomb)**: The resume data cache is decompressed using `inflateSync()` without limiting the decompressed output size. A small compressed payload can expand to hundreds of megabytes or gigabytes, causing memory exhaustion. Both attack vectors result in a fatal V8 out-of-memory error (`FATAL ERROR: Reached heap limit Allocation failed - JavaScript heap out of memory`) causing the Node.js process to terminate. The zipbomb variant is particularly dangerous as it can bypass reverse proxy request size limits while still causing large memory allocation on the server. To be affected you must have an application running with `experimental.ppr: true` or `cacheComponents: true` configured along with the NEXT_PRIVATE_MINIMAL_MODE=1 environment variable. Strongly consider upgrading to 15.6.0-canary.61 or 16.1.5 to reduce risk and prevent availability issues in Next applications.
Published 2026-01-26 · Analyzed
7.5EPSS 0.004
CVE-2021-37699
Open Redirect in Next.js versions below 11.1.0
Published 2021-08-11 · Modified
6.9EPSS 0.010
CVE-2026-29057
Next.js: HTTP request smuggling in rewrites
Published 2026-03-18 · Analyzed
6.5EPSS 0.005
CVE-2026-64644
Next.js: Denial of Service in the Image Optimization API using SVGs
Published 2026-07-27 · Analyzed
6.3EPSS 0.007
CVE-2026-64646
Next.js: Unbounded Server Action payload in Edge runtime
Published 2026-07-27 · Analyzed
6.3EPSS 0.005
CVE-2026-64643
Next.js: Unauthenticated Disclosure of Internal Server Function endpoints
Published 2026-07-27 · Analyzed
6.3EPSS 0.005
CVE-2026-64647
Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies
Published 2026-07-27 · Analyzed
6.3EPSS 0.003
CVE-2025-57752
Next.js Affected by Cache Key Confusion for Image Optimization API Routes
Published 2025-08-29 · Analyzed
6.2EPSS 0.003
CVE-2020-15242
Open Redirect in Next.js
Published 2020-10-08 · Modified
6.1EPSS 0.008
1 / 2Next →