Vercel / Next.js
64 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-94484 | Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitution and persistent denial of service | MEDIUM | 6.3 | Oct 2, 2026 |
| CVE-2026-94485 | Next.js: Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass | MEDIUM | 6.3 | Oct 2, 2026 |
| CVE-2026-94483 | Next.js: Server-Side Request Forgery in Image Optimization | HIGH | 8.3 | Oct 2, 2026 |
| CVE-2026-94543 | Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications | MEDIUM | 6.3 | Oct 2, 2026 |
| CVE-2026-94544 | Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages | MEDIUM | 6.3 | Oct 2, 2026 |
| CVE-2026-94486 | Next.js: Information disclosure in the Next.js development server's Model Context Protocol endpoint | LOW | 2.3 | Oct 2, 2026 |
| CVE-2026-103004 | next.js cache leak on warm `use cache` handlers accessing root param | MEDIUM | 6.3 | Oct 1, 2026 |
| CVE-2026-75604 | Next.js: Unauthenticated Remote Code Execution on windows-hosted servers | CRITICAL | 9.0 | Sep 1, 2026 |
| CVE-2026-64649 | Next.js: Server-Side Request Forgery in Server Actions on Custom Servers | HIGH | 8.3 | Jul 27, 2026 |
| CVE-2026-64648 | Next.js: Response Body Cache Confusion for Requests Containing Bodies | MEDIUM | 6.0 | Jul 27, 2026 |
| CVE-2026-64647 | Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies | MEDIUM | 6.3 | Jul 27, 2026 |
| CVE-2026-64646 | Next.js: Unbounded Server Action payload in Edge runtime | MEDIUM | 6.3 | Jul 27, 2026 |
| CVE-2026-64644 | Next.js: Denial of Service in the Image Optimization API using SVGs | MEDIUM | 6.3 | Jul 27, 2026 |
| CVE-2026-64643 | Next.js: Unauthenticated Disclosure of Internal Server Function endpoints | MEDIUM | 6.3 | Jul 27, 2026 |
| CVE-2026-64642 | Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale | HIGH | 8.3 | Jul 27, 2026 |
| CVE-2026-64641 | Next.js: Denial of Service in App Router using Server Actions | HIGH | 8.2 | Jul 27, 2026 |
| CVE-2026-64645 | Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname | HIGH | 8.3 | Jul 27, 2026 |
| CVE-2026-45109 | Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes | HIGH | 7.5 | May 13, 2026 |
| CVE-2026-44582 | Next.js: Cache poisoning via collisions in React Server Component cache-busting | LOW | 3.7 | May 13, 2026 |
| CVE-2026-44581 | Next.js: Cross-site scripting in App Router applications using CSP nonces | MEDIUM | 4.7 | May 13, 2026 |
| CVE-2026-44580 | Next.js: Cross-site scripting in beforeInteractive scripts with untrusted input | MEDIUM | 6.1 | May 13, 2026 |
| CVE-2026-44579 | Next.js: Denial of Service via connection exhaustion in applications using Cache Components | HIGH | 7.5 | May 13, 2026 |
| CVE-2026-44578 | Next.js: Server-side request forgery in applications using WebSocket upgrades | HIGH | 8.6 | May 13, 2026 |
| CVE-2026-44577 | Next.js: Denial of Service in the Image Optimization API | HIGH | 7.5 | May 13, 2026 |
| CVE-2026-44576 | Next.js: Cache poisoning in React Server Component responses | MEDIUM | 5.4 | May 13, 2026 |
Showing 1 to 25 of 64 CVEs