CVE-2026-44578
- EPSS 5.04%
- Veröffentlicht 13.05.2026 17:01:38
- Zuletzt bearbeitet 14.05.2026 18:34:38
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket up...
CVE-2026-44572
- EPSS 0.01%
- Veröffentlicht 13.05.2026 16:16:58
- Zuletzt bearbeitet 15.05.2026 15:46:08
Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When th...
CVE-2026-29057
- EPSS 0.04%
- Veröffentlicht 18.03.2026 00:30:27
- Zuletzt bearbeitet 18.03.2026 19:49:19
Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfe...
CVE-2026-27980
- EPSS 0.02%
- Veröffentlicht 18.03.2026 00:23:34
- Zuletzt bearbeitet 18.03.2026 19:52:54
Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unboun...
CVE-2026-27979
- EPSS 0.02%
- Veröffentlicht 18.03.2026 00:13:29
- Zuletzt bearbeitet 18.03.2026 20:04:17
Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies with...
CVE-2026-27978
- EPSS 0.01%
- Veröffentlicht 17.03.2026 23:59:22
- Zuletzt bearbeitet 18.03.2026 20:05:48
Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a "missing" origin during Server Action CSRF validation. As a result, requests from opaque co...
CVE-2026-27977
- EPSS 0.01%
- Veröffentlicht 17.03.2026 23:56:24
- Zuletzt bearbeitet 18.03.2026 20:08:59
Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `...
CVE-2025-59472
- EPSS 0.09%
- Veröffentlicht 26.01.2026 21:43:05
- Zuletzt bearbeitet 24.02.2026 18:24:35
A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-c...
CVE-2025-59471
- EPSS 0.03%
- Veröffentlicht 26.01.2026 21:43:05
- Zuletzt bearbeitet 13.02.2026 15:03:20
A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing ...
CVE-2025-67779
- EPSS 0.66%
- Veröffentlicht 11.12.2025 23:36:20
- Zuletzt bearbeitet 12.12.2025 19:16:03
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe...