Vercel

Next.Js

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 5.04%
  • Veröffentlicht 13.05.2026 17:01:38
  • Zuletzt bearbeitet 14.05.2026 18:34:38

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket up...

  • EPSS 0.01%
  • Veröffentlicht 13.05.2026 16:16:58
  • Zuletzt bearbeitet 15.05.2026 15:46:08

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When th...

  • EPSS 0.04%
  • Veröffentlicht 18.03.2026 00:30:27
  • Zuletzt bearbeitet 18.03.2026 19:49:19

Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfe...

  • EPSS 0.02%
  • Veröffentlicht 18.03.2026 00:23:34
  • Zuletzt bearbeitet 18.03.2026 19:52:54

Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unboun...

  • EPSS 0.02%
  • Veröffentlicht 18.03.2026 00:13:29
  • Zuletzt bearbeitet 18.03.2026 20:04:17

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies with...

  • EPSS 0.01%
  • Veröffentlicht 17.03.2026 23:59:22
  • Zuletzt bearbeitet 18.03.2026 20:05:48

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a "missing" origin during Server Action CSRF validation. As a result, requests from opaque co...

  • EPSS 0.01%
  • Veröffentlicht 17.03.2026 23:56:24
  • Zuletzt bearbeitet 18.03.2026 20:08:59

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `...

  • EPSS 0.09%
  • Veröffentlicht 26.01.2026 21:43:05
  • Zuletzt bearbeitet 24.02.2026 18:24:35

A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-c...

  • EPSS 0.03%
  • Veröffentlicht 26.01.2026 21:43:05
  • Zuletzt bearbeitet 13.02.2026 15:03:20

A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing ...

Medienbericht
  • EPSS 0.66%
  • Veröffentlicht 11.12.2025 23:36:20
  • Zuletzt bearbeitet 12.12.2025 19:16:03

It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe...