Next
This hub aggregates every CVE we track for Next, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
39
CVEs tracked
3
Critical
15
High
0
In CISA KEV
Severity distribution
MEDIUM19HIGH15CRITICAL3LOW2
Monthly trend
1
0
1
1
0
1
1
0
1
1
2
0
2
3
0
0
0
0
2
0
2
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Next.
- CVE-2026-27978Next.js: null origin can bypass Server Actions CSRF checks4.3
- CVE-2026-27977Next.js: null origin can bypass dev HMR websocket CSRF checks5.4
- CVE-2025-59471A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads ex...5.9
- CVE-2025-59472A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with...5.9
- CVE-2025-57752Next.js Affected by Cache Key Confusion for Image Optimization API Routes6.2
- CVE-2025-55173Next.js Content Injection Vulnerability for Image Optimization4.3
- CVE-2025-57822Next.js Improper Middleware Redirect Handling Leads to SSRF6.5
- CVE-2025-49826Next.js DoS vulnerability via cache poisoning7.5
- CVE-2025-49005Next.js cache poisoning due to omission of Vary header3.7
- CVE-2025-48068Information exposure in Next.js dev server due to lack of origin verification4.3
- CVE-2025-32421Next.js Race Condition to Cache Poisoning3.7
- CVE-2025-30218Next.js may leak x-middleware-subrequest-id to external hosts5.9
- CVE-2025-29927Authorization Bypass in Next.js Middleware9.1
- CVE-2024-56332Next.js Vulnerable to Denial of Service (DoS) with Server Actions5.3
- CVE-2024-51479Authorization bypass in Next.js7.5
Product normalization is registry-driven with AI assist and human review. How it works