Next.js: Denial of Service in App Router using Server Actions
Published Jul 27, 2026
8.2
HIGHCVSS 4.0
EPSS 0.86%
Description
Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. This issue has been fixed in versions 15.5.21 and 16.2.11.
Affected products
-
- Version >= 13.0.0, < 15.5.21StatusaffectedConstraints-
- Version >= 16.0.0, < 16.2.11StatusaffectedConstraints-
- Version
No data.
Streams for Apache Kafka 3.2.1
next
Fixed · RHSA-2026:54435
Cryostat 4
i18next
Not affected
Red Hat 3scale API Management Platform 2
3scale-amp2/backend-rhel8
Not affected
Red Hat 3scale API Management Platform 2
3scale-amp2/system-rhel7
Not affected
Red Hat AMQ Broker 7
i18next
Not affected
Red Hat Build of Keycloak
quarkus-websockets-next-spi
Affected
Red Hat Ceph Storage 5
rhceph/rhceph-5-dashboard-rhel8
Affected
Red Hat Ceph Storage 6
rhceph/rhceph-6-dashboard-rhel9
Affected
Red Hat Ceph Storage 7
rhceph/grafana-rhel9
Affected
Red Hat Ceph Storage 8
rhceph/grafana-rhel9
Affected
Red Hat Ceph Storage 9
rhceph/alloy-rhel10
Affected
Red Hat Connectivity Link 1
rhcl-1/rhcl-console-plugin-rhel9
Not affected
Red Hat Data Grid 8
i18next
Not affected
Red Hat Enterprise Linux 10
firefox
Not affected
Red Hat Enterprise Linux 10
thunderbird
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 8
thunderbird
Not affected
Red Hat Enterprise Linux 9
firefox
Not affected
Red Hat Enterprise Linux 9
thunderbird
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Affected
Red Hat JBoss Enterprise Application Platform 7
process-nextick-args
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
i18next
Not affected
Red Hat Openshift Data Foundation 4
odf4/mcg-core-rhel9
Not affected
Red Hat Single Sign-On 7
process-nextick-args
Fix deferred
Red Hat Trusted Artifact Signer
rhtas/rekor-search-ui-rhel9
Not affected
Red Hat build of Apache Camel - HawtIO 4
quarkus-websockets-next-spi
Not affected
Red Hat build of Apache Camel 4 for Quarkus 3
quarkus-websockets-next-spi
Not affected
Red Hat build of Apache Camel for Spring Boot 4
i18next
Not affected
Red Hat build of Apicurio Registry 3
quarkus-websockets-next-spi
Not affected
Red Hat build of Quarkus
quarkus-websockets-next-deployment
Not affected
streams for Apache Kafka 2
next
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Streams for Apache Kafka 3.2.1 | next | Fixed | RHSA-2026:54435 |
| Cryostat 4 | i18next | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp2/backend-rhel8 | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp2/system-rhel7 | Not affected | n/a |
| Red Hat AMQ Broker 7 | i18next | Not affected | n/a |
| Red Hat Build of Keycloak | quarkus-websockets-next-spi | Affected | n/a |
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Affected | n/a |
| Red Hat Ceph Storage 6 | rhceph/rhceph-6-dashboard-rhel9 | Affected | n/a |
| Red Hat Ceph Storage 7 | rhceph/grafana-rhel9 | Affected | n/a |
| Red Hat Ceph Storage 8 | rhceph/grafana-rhel9 | Affected | n/a |
| Red Hat Ceph Storage 9 | rhceph/alloy-rhel10 | Affected | n/a |
| Red Hat Connectivity Link 1 | rhcl-1/rhcl-console-plugin-rhel9 | Not affected | n/a |
| Red Hat Data Grid 8 | i18next | Not affected | n/a |
| Red Hat Enterprise Linux 10 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 10 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | process-nextick-args | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | i18next | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel9 | Not affected | n/a |
| Red Hat Single Sign-On 7 | process-nextick-args | Fix deferred | n/a |
| Red Hat Trusted Artifact Signer | rhtas/rekor-search-ui-rhel9 | Not affected | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | quarkus-websockets-next-spi | Not affected | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | quarkus-websockets-next-spi | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | i18next | Not affected | n/a |
| Red Hat build of Apicurio Registry 3 | quarkus-websockets-next-spi | Not affected | n/a |
| Red Hat build of Quarkus | quarkus-websockets-next-deployment | Not affected | n/a |
| streams for Apache Kafka 2 | next | Affected | n/a |
next
npm
Introduced 16.0.0 Fixed 16.2.11next
npm
Introduced 13.0.0 Fixed 15.5.21
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | next | 16.0.0 | 16.2.11 |
| npm | next | 13.0.0 | 15.5.21 |
Remediation
Red Hat statement
Important: A denial of service flaw exists in Next.js applications utilizing the App Router with Server Actions. Crafted requests can lead to excessive CPU consumption, potentially disrupting service availability for affected Red Hat products that embed or depend on vulnerable Next.js versions.
References (11)
- https://access.redhat.com/security/cve/CVE-2026-64641 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2507613 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-49381 Advisory
- https://github.com/advisories/GHSA-m99w-x7hq-7vfj Advisory
- https://github.com/vercel/next.js/commit/019628571641dec57aaf349ba0c360e3964e6f12 x_refsource_MISCPatch
- https://github.com/vercel/next.js/pull/96013 x_refsource_MISCIssue TrackingPatch
- https://github.com/vercel/next.js/releases/tag/v15.5.21 x_refsource_MISCProductRelease Notes
- https://github.com/vercel/next.js/releases/tag/v16.2.11 x_refsource_MISCProductRelease Notes
- https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-64641
- https://www.cve.org/CVERecord?id=CVE-2026-64641
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-64641 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2507613 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-49381 | Advisory | |
| https://github.com/advisories/GHSA-m99w-x7hq-7vfj | Advisory | |
| https://github.com/vercel/next.js/commit/019628571641dec57aaf349ba0c360e3964e6f12 | x_refsource_MISCPatch | |
| https://github.com/vercel/next.js/pull/96013 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/vercel/next.js/releases/tag/v15.5.21 | x_refsource_MISCProductRelease Notes | |
| https://github.com/vercel/next.js/releases/tag/v16.2.11 | x_refsource_MISCProductRelease Notes | |
| https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-64641 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-64641 |
Change history (0)
No recorded changes yet.