Vercel

Next.Js

35 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 18.03.2026 00:30:27
  • Zuletzt bearbeitet 18.03.2026 19:49:19

Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfe...

  • EPSS 0.02%
  • Veröffentlicht 18.03.2026 00:23:34
  • Zuletzt bearbeitet 18.03.2026 19:52:54

Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unboun...

  • EPSS 0.02%
  • Veröffentlicht 18.03.2026 00:13:29
  • Zuletzt bearbeitet 18.03.2026 20:04:17

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies with...

  • EPSS 0.01%
  • Veröffentlicht 17.03.2026 23:59:22
  • Zuletzt bearbeitet 18.03.2026 20:05:48

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a "missing" origin during Server Action CSRF validation. As a result, requests from opaque co...

  • EPSS 0.01%
  • Veröffentlicht 17.03.2026 23:56:24
  • Zuletzt bearbeitet 18.03.2026 20:08:59

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `...

  • EPSS 0.09%
  • Veröffentlicht 26.01.2026 21:43:05
  • Zuletzt bearbeitet 24.02.2026 18:24:35

A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-c...

  • EPSS 0.03%
  • Veröffentlicht 26.01.2026 21:43:05
  • Zuletzt bearbeitet 13.02.2026 15:03:20

A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing ...

Medienbericht
  • EPSS 0.13%
  • Veröffentlicht 11.12.2025 23:36:20
  • Zuletzt bearbeitet 12.12.2025 19:16:03

It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe...

Medienbericht
  • EPSS 23.57%
  • Veröffentlicht 11.12.2025 20:16:00
  • Zuletzt bearbeitet 15.12.2025 17:15:53

A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react...

Medienbericht Exploit
  • EPSS 23.43%
  • Veröffentlicht 11.12.2025 20:16:00
  • Zuletzt bearbeitet 12.12.2025 18:18:19

An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, a...