Vercel

Next.Js

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 13.05.2026 17:16:23
  • Zuletzt bearbeitet 13.05.2026 20:00:59

Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enf...

  • EPSS 0.02%
  • Veröffentlicht 13.05.2026 17:16:23
  • Zuletzt bearbeitet 14.05.2026 13:44:18

Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response va...

  • EPSS 0.05%
  • Veröffentlicht 13.05.2026 17:16:22
  • Zuletzt bearbeitet 14.05.2026 12:38:11

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-s...

  • EPSS 0.01%
  • Veröffentlicht 13.05.2026 17:16:22
  • Zuletzt bearbeitet 14.05.2026 12:37:00

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specia...

  • EPSS 0.05%
  • Veröffentlicht 13.05.2026 17:16:22
  • Zuletzt bearbeitet 14.05.2026 12:24:22

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protec...

  • EPSS 0.01%
  • Veröffentlicht 13.05.2026 17:11:07
  • Zuletzt bearbeitet 14.05.2026 14:14:06

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18...

  • EPSS 0.01%
  • Veröffentlicht 13.05.2026 17:08:22
  • Zuletzt bearbeitet 14.05.2026 18:15:03

Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient respons...

  • EPSS 0.01%
  • Veröffentlicht 13.05.2026 17:07:15
  • Zuletzt bearbeitet 14.05.2026 18:30:24

Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In a...

  • EPSS 0.01%
  • Veröffentlicht 13.05.2026 17:06:05
  • Zuletzt bearbeitet 14.05.2026 18:33:34

Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected ve...

  • EPSS 0.02%
  • Veröffentlicht 13.05.2026 17:04:28
  • Zuletzt bearbeitet 14.05.2026 18:34:04

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST re...