CVE-2026-44575
- EPSS 1.59%
- Veröffentlicht 13.05.2026 17:16:22
- Zuletzt bearbeitet 13.08.2026 13:19:03
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-s...
CVE-2026-44574
- EPSS 0.64%
- Veröffentlicht 13.05.2026 17:16:22
- Zuletzt bearbeitet 13.08.2026 13:19:03
Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specia...
CVE-2026-45109
- EPSS 0.57%
- Veröffentlicht 13.05.2026 17:11:07
- Zuletzt bearbeitet 13.08.2026 13:19:05
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18...
CVE-2026-44582
- EPSS 0.22%
- Veröffentlicht 13.05.2026 17:08:22
- Zuletzt bearbeitet 14.05.2026 18:15:03
Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient respons...
CVE-2026-44581
- EPSS 0.22%
- Veröffentlicht 13.05.2026 17:07:15
- Zuletzt bearbeitet 14.05.2026 18:30:24
Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In a...
CVE-2026-44580
- EPSS 0.21%
- Veröffentlicht 13.05.2026 17:06:05
- Zuletzt bearbeitet 14.05.2026 18:33:34
Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected ve...
CVE-2026-44579
- EPSS 0.75%
- Veröffentlicht 13.05.2026 17:04:28
- Zuletzt bearbeitet 13.08.2026 13:19:04
Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST re...
CVE-2026-44578
- EPSS 38.87%
- Veröffentlicht 13.05.2026 17:01:38
- Zuletzt bearbeitet 13.08.2026 13:19:04
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket up...
CVE-2026-44572
- EPSS 0.28%
- Veröffentlicht 13.05.2026 16:16:58
- Zuletzt bearbeitet 15.05.2026 15:46:08
Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When th...
CVE-2026-29057
- EPSS 0.43%
- Veröffentlicht 18.03.2026 00:30:27
- Zuletzt bearbeitet 18.03.2026 19:49:19
Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfe...