Vercel

Next.Js

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 92.32%
  • Veröffentlicht 14.05.2024 15:38:42
  • Zuletzt bearbeitet 10.09.2025 15:43:33

Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also...

  • EPSS 0.64%
  • Veröffentlicht 14.05.2024 15:38:41
  • Zuletzt bearbeitet 10.09.2025 15:36:59

Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 22.10.2023 03:15:07
  • Zuletzt bearbeitet 21.11.2024 08:28:15

Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.

  • EPSS 0.41%
  • Veröffentlicht 31.08.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:15

Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CVE: Next.js version 12.2.3, Node.js version above v15.0.0 being used with strict `unhandledRejection` ...

  • EPSS 1.38%
  • Veröffentlicht 17.02.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:49:00

Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User Interface (UI) Misrepresentation of Critical Information. In order to be affected, the `next.config.js` file must have an `images.do...

  • EPSS 0.93%
  • Veröffentlicht 28.01.2022 22:15:16
  • Zuletzt bearbeitet 21.11.2024 06:45:18

Next.js is a React framework. Starting with version 12.0.0 and prior to version 12.0.9, vulnerable code could allow a bad actor to trigger a denial of service attack for anyone using i18n functionality. In order to be affected by this CVE, one must u...

  • EPSS 2.73%
  • Veröffentlicht 10.12.2021 00:15:11
  • Zuletzt bearbeitet 21.11.2024 06:29:49

Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to be affected by this issue, the deployment must use Next.js versions above 11.1.0 and below 12.0.5, Nod...

  • EPSS 0.7%
  • Veröffentlicht 31.08.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:18:48

Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability. In order for an instance to be affected by the vulnerability, the `next.config.js` file must have `images.domains` array assigne...

  • EPSS 0.43%
  • Veröffentlicht 12.08.2021 00:15:06
  • Zuletzt bearbeitet 21.11.2024 06:15:44

Next.js is an open source website development framework to be used with the React library. In affected versions specially encoded paths could be used when pages/_error.js was statically generated allowing an open redirect to occur to an external site...

  • EPSS 0.21%
  • Veröffentlicht 08.10.2020 20:15:19
  • Zuletzt bearbeitet 21.11.2024 05:05:10

Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to allow an open redirect to occur to an external site. In general, this redirect does not directly harm us...