Next.js
This hub aggregates every CVE we track for Next.js, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
64
CVEs tracked
4
Critical
24
High
1
In CISA KEV
Severity distribution
MEDIUM32HIGH24LOW4CRITICAL4
Monthly trend
1
0
1
1
0
1
1
2
0
2
3
0
0
0
4
3
0
5
1
13
0
9
0
1
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Next.js.
- CVE-2026-75604Next.js: Unauthenticated Remote Code Execution on windows-hosted servers9.0
- CVE-2026-64649Next.js: Server-Side Request Forgery in Server Actions on Custom Servers6.5
- CVE-2026-64648Next.js: Response Body Cache Confusion for Requests Containing Bodies5.4
- CVE-2026-64647Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies5.4
- CVE-2026-64646Next.js: Unbounded Server Action payload in Edge runtime5.3
- CVE-2026-64644Next.js: Denial of Service in the Image Optimization API using SVGs5.3
- CVE-2026-64643Next.js: Unauthenticated Disclosure of Internal Server Function endpoints5.3
- CVE-2026-64642Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale8.2
- CVE-2026-64641Next.js: Denial of Service in App Router using Server Actions7.5
- CVE-2026-64645Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname6.1
- CVE-2026-45109Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes7.5
- CVE-2026-44582Next.js: Cache poisoning via collisions in React Server Component cache-busting3.7
- CVE-2026-44581Next.js: Cross-site scripting in App Router applications using CSP nonces4.7
- CVE-2026-44580Next.js: Cross-site scripting in beforeInteractive scripts with untrusted input6.1
- CVE-2026-44579Next.js: Denial of Service via connection exhaustion in applications using Cache Components7.5
Product normalization is registry-driven with AI assist and human review. How it works