Vercel

Next.Js

25 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.73%
  • Veröffentlicht 03.01.2025 21:15:13
  • Zuletzt bearbeitet 10.09.2025 15:48:41

Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, Next.js is vulnerable to a Denial of Service (DoS) attack that allows attackers to construct requests...

  • EPSS 80.35%
  • Veröffentlicht 17.12.2024 19:15:06
  • Zuletzt bearbeitet 10.09.2025 15:48:08

Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly...

  • EPSS 0.46%
  • Veröffentlicht 14.10.2024 18:15:05
  • Zuletzt bearbeitet 08.11.2024 15:39:21

Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in the image optimization feature which allows for a potential Denial of Service (DoS) condition which c...

  • EPSS 52.62%
  • Veröffentlicht 17.09.2024 22:15:02
  • Zuletzt bearbeitet 10.09.2025 15:46:05

Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When t...

  • EPSS 0.51%
  • Veröffentlicht 10.07.2024 20:15:04
  • Zuletzt bearbeitet 10.09.2025 15:44:17

Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting the availability of the server. his vulnerability was resolved in Next.js 13.5 and later.

  • EPSS 92.32%
  • Veröffentlicht 14.05.2024 15:38:42
  • Zuletzt bearbeitet 10.09.2025 15:43:33

Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also...

  • EPSS 0.64%
  • Veröffentlicht 14.05.2024 15:38:41
  • Zuletzt bearbeitet 10.09.2025 15:36:59

Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 22.10.2023 03:15:07
  • Zuletzt bearbeitet 21.11.2024 08:28:15

Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.

  • EPSS 0.41%
  • Veröffentlicht 31.08.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:15

Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CVE: Next.js version 12.2.3, Node.js version above v15.0.0 being used with strict `unhandledRejection` ...

  • EPSS 1.38%
  • Veröffentlicht 17.02.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:49:00

Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User Interface (UI) Misrepresentation of Critical Information. In order to be affected, the `next.config.js` file must have an `images.do...