Back

HIGH

Next.js: Denial of Service in App Router using Server Actions

Published Jul 27, 2026

Description

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. This issue has been fixed in versions 15.5.21 and 16.2.11.

Affected products

Remediation

Red Hat statement

Important: A denial of service flaw exists in Next.js applications utilizing the App Router with Server Actions. Crafted requests can lead to excessive CPU consumption, potentially disrupting service availability for affected Red Hat products that embed or depend on vulnerable Next.js versions.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 27, 2026
Updated Jul 27, 2026
Reserved Jul 20, 2026
CISA Vulnrichment
Updated Jul 27, 2026
NVD
Status Analyzed
Modified Jul 29, 2026
Red Hat
Severity Important
Public date Jul 27, 2026
ENISA EUVD
Assigner GitHub_M
Published Jul 27, 2026
Updated Jul 27, 2026
Exploited since n/a
EUVD-2026-49381 GHSA-M99W-X7HQ-7VFJ