CVE-2026-29057
- EPSS 0.07%
- Veröffentlicht 18.03.2026 00:30:27
- Zuletzt bearbeitet 18.03.2026 19:49:19
Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfe...
CVE-2026-27980
- EPSS 0.02%
- Veröffentlicht 18.03.2026 00:23:34
- Zuletzt bearbeitet 18.03.2026 19:52:54
Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unboun...
CVE-2026-27979
- EPSS 0.02%
- Veröffentlicht 18.03.2026 00:13:29
- Zuletzt bearbeitet 18.03.2026 20:04:17
Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies with...
CVE-2026-27978
- EPSS 0.01%
- Veröffentlicht 17.03.2026 23:59:22
- Zuletzt bearbeitet 18.03.2026 20:05:48
Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a "missing" origin during Server Action CSRF validation. As a result, requests from opaque co...
CVE-2026-27977
- EPSS 0.01%
- Veröffentlicht 17.03.2026 23:56:24
- Zuletzt bearbeitet 18.03.2026 20:08:59
Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `...
CVE-2025-59472
- EPSS 0.09%
- Veröffentlicht 26.01.2026 21:43:05
- Zuletzt bearbeitet 24.02.2026 18:24:35
A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-c...
CVE-2025-59471
- EPSS 0.03%
- Veröffentlicht 26.01.2026 21:43:05
- Zuletzt bearbeitet 13.02.2026 15:03:20
A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing ...
CVE-2025-67779
- EPSS 0.13%
- Veröffentlicht 11.12.2025 23:36:20
- Zuletzt bearbeitet 12.12.2025 19:16:03
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe...
CVE-2025-55184
- EPSS 23.57%
- Veröffentlicht 11.12.2025 20:16:00
- Zuletzt bearbeitet 15.12.2025 17:15:53
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react...
CVE-2025-55183
- EPSS 23.43%
- Veröffentlicht 11.12.2025 20:16:00
- Zuletzt bearbeitet 12.12.2025 18:18:19
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, a...