VendorsVercelnext.jsall versions
Vulnerabilities

Vercel Next.js

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-2026-44580
Next.js: Cross-site scripting in beforeInteractive scripts with untrusted input
Published 2026-05-13 · Analyzed
6.1EPSS 0.003
CVE-2026-64648
Next.js: Response Body Cache Confusion for Requests Containing Bodies
Published 2026-07-27 · Analyzed
6.0EPSS 0.003
CVE-2025-30218
Next.js may leak x-middleware-subrequest-id to external hosts
Published 2025-04-02 · Analyzed
5.9EPSS 0.004
CVE-2026-44572
Next.js: Middleware / Proxy redirects can be cache-poisoned
Published 2026-05-13 · Analyzed
5.9EPSS 0.002
CVE-2026-44576
Next.js: Cache poisoning in React Server Component responses
Published 2026-05-13 · Analyzed
5.4EPSS 0.003
CVE-2026-27977
Next.js: null origin can bypass dev HMR websocket CSRF checks
Published 2026-03-17 · Analyzed
5.4EPSS 0.002
CVE-2025-55183
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.
Published 2025-12-11 · Analyzed
5.3EPSS 0.642
CVE-2022-36046
Unexpected server crash in Next.js version 12.2.3
Published 2022-08-31 · Modified
5.3EPSS 0.012
CVE-2024-56332
Next.js Vulnerable to Denial of Service (DoS) with Server Actions
Published 2025-01-03 · Analyzed
5.3EPSS 0.008
CVE-2026-27978
Next.js: null origin can bypass Server Actions CSRF checks
Published 2026-03-17 · Analyzed
5.3EPSS 0.002
CVE-2026-44581
Next.js: Cross-site scripting in App Router applications using CSP nonces
Published 2026-05-13 · Analyzed
4.7EPSS 0.002
CVE-2025-55173
Next.js Content Injection Vulnerability for Image Optimization
Published 2025-08-29 · Analyzed
4.3EPSS 0.005
CVE-2025-48068
Information exposure in Next.js dev server due to lack of origin verification
Published 2025-05-30 · Analyzed
4.3EPSS 0.002
CVE-2025-32421
Next.js Race Condition to Cache Poisoning
Published 2025-05-14 · Analyzed
3.7EPSS 0.008
CVE-2025-49005
Next.js cache poisoning due to omission of Vary header
Published 2025-07-03 · Analyzed
3.7EPSS 0.005
CVE-2026-44582
Next.js: Cache poisoning via collisions in React Server Component cache-busting
Published 2026-05-13 · Analyzed
3.7EPSS 0.002
← Prev2 / 2