Next.js: Cross-site scripting in beforeInteractive scripts with untrusted input
Published May 13, 2026
6.1
MEDIUMCVSS 3.1
EPSS 0.25%
Description
Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vulnerability is fixed in 15.5.16 and 16.2.5.
Affected products
-
- Version >= 13.0.0, < 15.5.16StatusaffectedConstraints-
- Version >= 16.0.0, < 16.2.5StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 10
nodejs22
Not affected
Red Hat Enterprise Linux 10
nodejs24
Not affected
Red Hat Enterprise Linux 8
nodejs:22/nodejs
Not affected
Red Hat Enterprise Linux 8
nodejs:24/nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs:22/nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs:24/nodejs
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Fix deferred
Red Hat Hardened Images
nodejs20
Not affected
Red Hat Hardened Images
nodejs22
Not affected
Red Hat Hardened Images
nodejs24
Not affected
Red Hat Hardened Images
nodejs25
Not affected
Red Hat Hardened Images
nodejs26
Not affected
Red Hat Trusted Artifact Signer
rhtas/rekor-search-ui-rhel9
Fix deferred
streams for Apache Kafka 3
next
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | nodejs22 | Not affected | n/a |
| Red Hat Enterprise Linux 10 | nodejs24 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:22/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:24/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:22/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:24/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Hardened Images | nodejs20 | Not affected | n/a |
| Red Hat Hardened Images | nodejs22 | Not affected | n/a |
| Red Hat Hardened Images | nodejs24 | Not affected | n/a |
| Red Hat Hardened Images | nodejs25 | Not affected | n/a |
| Red Hat Hardened Images | nodejs26 | Not affected | n/a |
| Red Hat Trusted Artifact Signer | rhtas/rekor-search-ui-rhel9 | Fix deferred | n/a |
| streams for Apache Kafka 3 | next | Fix deferred | n/a |
next
npm
Introduced 13.0.0 Fixed 15.5.16next
npm
Introduced 16.0.0 Fixed 16.2.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | next | 13.0.0 | 15.5.16 |
| npm | next | 16.0.0 | 16.2.5 |
Remediation
Red Hat statement
This is a Moderate cross-site scripting (XSS) vulnerability affecting Next.js applications. The flaw occurs when applications employ `beforeInteractive` scripts with unsanitized, untrusted content, enabling remote attackers to execute arbitrary JavaScript. The requirement for this specific script strategy and attacker-controlled input limits the overall exposure in Red Hat deployments.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-44580 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2477186 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30082 Advisory
- https://github.com/advisories/GHSA-gx5p-jg67-6x7h Advisory
- https://github.com/vercel/next.js/releases/tag/v15.5.16
- https://github.com/vercel/next.js/releases/tag/v16.2.5
- https://github.com/vercel/next.js/security/advisories/GHSA-gx5p-jg67-6x7h x_refsource_CONFIRMMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-44580
- https://www.cve.org/CVERecord?id=CVE-2026-44580
Change history (0)
No recorded changes yet.