Security-Changelog

Next.js

66 Fixes · 30 high/critical

Quelle: GitHub Advisory Database, stündlich abgerufen. · Zuletzt geprüft 21.09.2026

Sept. 2026

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

Betroffen: >= 10.0.0, < 15.5.24 · >= 16.0.0, < 16.3.3Behoben in 15.5.24, 16.3.3
criticalGHSA-p293-qw3h-jr36CVE-2026-75604
Sept. 2026

Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

Betroffen: >= 13.4.0, < 15.5.24 · >= 16.0.0, < 16.3.3Behoben in 15.5.24, 16.3.3
highGHSA-89xv-2m56-2m9xCVE-2026-64649
Juli 2026

Next.js: Server-Side Request Forgery in Server Actions on custom servers

Betroffen: >= 14.1.1, < 15.5.21 · >= 16.0.0, < 16.2.11Behoben in 15.5.21, 16.2.11
mediumGHSA-68g3-v927-f742CVE-2026-64648
Juli 2026

Next.js: Cache confusion of response bodies for requests with bodies

Betroffen: >= 13.0.0, < 15.5.21 · >= 16.0.0, < 16.2.11Behoben in 15.5.21, 16.2.11
mediumGHSA-4633-3j49-mh5qCVE-2026-64647
Juli 2026

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

Betroffen: >= 13.0.0, < 15.5.21 · >= 16.0.0, < 16.2.11Behoben in 15.5.21, 16.2.11
mediumGHSA-4c39-4ccg-62r3CVE-2026-64646
Juli 2026

Next.js: Unbounded Server Action payload in Edge runtime

Betroffen: >= 13.0.0, < 15.5.21 · >= 16.0.0, < 16.2.11Behoben in 15.5.21, 16.2.11
highGHSA-p9j2-gv94-2wf4CVE-2026-64645
Juli 2026

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

Betroffen: >= 12.0.0, < 15.5.21 · >= 16.0.0, < 16.2.11Behoben in 15.5.21, 16.2.11
mediumGHSA-q8wf-6r8g-63chCVE-2026-64644
Juli 2026

Next.js: Denial of Service in the Image Optimization API using SVGs

Betroffen: >= 15.5.0, < 15.5.21 · >= 16.0.0, < 16.2.11Behoben in 15.5.21, 16.2.11
mediumGHSA-955p-x3mx-jcvpCVE-2026-64643
Juli 2026

Next.js: Unauthenticated disclosure of internal Server Function endpoints

Betroffen: >= 13.0.0, < 15.5.21 · >= 16.0.0, < 16.2.11Behoben in 15.5.21, 16.2.11
highGHSA-6gpp-xcg3-4w24CVE-2026-64642
Juli 2026

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

Betroffen: >= 16.0.0, < 16.2.11Behoben in 16.2.11
Alle anzeigen 56
highGHSA-m99w-x7hq-7vfjCVE-2026-64641
Juli 2026

Next.js: Denial of Service in App Router using Server Actions

Betroffen: >= 13.0.0, < 15.5.21 · >= 16.0.0, < 16.2.11Behoben in 15.5.21, 16.2.11
highGHSA-26hh-7cqf-hhc6CVE-2026-45109
Mai 2026

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up

Betroffen: >= 15.2.0, < 15.5.18 · >= 16.0.0, < 16.2.6Behoben in 15.5.18, 16.2.6
lowGHSA-3g8h-86w9-wvmqCVE-2026-44572
Mai 2026

Next.js's Middleware / Proxy redirects can be cache-poisoned

Betroffen: >= 12.2.0, < 15.5.16 · >= 16.0.0, < 16.2.5Behoben in 15.5.16, 16.2.5
mediumGHSA-ffhc-5mcf-pf4qCVE-2026-44581
Mai 2026

Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces

Betroffen: >= 13.4.0, < 15.5.16 · >= 16.0.0, < 16.2.5Behoben in 15.5.16, 16.2.5
lowGHSA-vfv6-92ff-j949CVE-2026-44582
Mai 2026

Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

Betroffen: >= 13.4.6, < 15.5.16 · >= 16.0.0, < 16.2.5Behoben in 15.5.16, 16.2.5
mediumGHSA-gx5p-jg67-6x7hCVE-2026-44580
Mai 2026

Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

Betroffen: >= 13.0.0, < 15.5.16 · >= 16.0.0, < 16.2.5Behoben in 15.5.16, 16.2.5
highGHSA-mg66-mrh9-m8jxCVE-2026-44579
Mai 2026

Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components

Betroffen: >= 15.0.0, < 15.5.16 · >= 16.0.0, < 16.2.5Behoben in 15.5.16, 16.2.5
mediumGHSA-h64f-5h5j-jqjhCVE-2026-44577
Mai 2026

Next.js has a Denial of Service in the Image Optimization API

Betroffen: >= 10.0.0, < 15.5.16 · >= 16.0.0, < 16.2.5Behoben in 15.5.16, 16.2.5
highGHSA-c4j6-fc7j-m34rCVE-2026-44578
Mai 2026

Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades

Betroffen: >= 13.4.13, < 15.5.16 · >= 16.0.0, < 16.2.5Behoben in 15.5.16, 16.2.5
mediumGHSA-wfc6-r584-vfw7CVE-2026-44576
Mai 2026

Next.js vulnerable to cache poisoning in React Server Component responses

Betroffen: >= 14.2.0, < 15.5.16 · >= 16.0.0, < 16.2.5Behoben in 15.5.16, 16.2.5
highGHSA-267c-6grr-h53fCVE-2026-44575
Mai 2026

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes

Betroffen: >= 15.2.0, < 15.5.16 · >= 16.0.0, < 16.2.5Behoben in 15.5.16, 16.2.5
highGHSA-492v-c6pp-mqqvCVE-2026-44574
Mai 2026

Next.js has a Middleware / Proxy bypass through dynamic route parameter injection

Betroffen: >= 15.4.0, < 15.5.16 · >= 16.0.0, < 16.2.5Behoben in 15.5.16, 16.2.5
highGHSA-36qx-fr4f-26g5CVE-2026-44573
Mai 2026

Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n

Betroffen: >= 12.2.0, < 15.5.16 · >= 16.0.0, < 16.2.5Behoben in 15.5.16, 16.2.5

Next.js Vulnerable to Denial of Service with Server Components

Betroffen: >= 13.0.0, < 15.5.16 · >= 16.0.0, < 16.2.5Behoben in 15.5.16, 16.2.5
Apr. 2026

Next.js has a Denial of Service with Server Components

Betroffen: >= 13.0.0, < 15.5.15 · >= 16.0.0-beta.0, < 16.2.3Behoben in 15.5.15, 16.2.3
mediumGHSA-ggv3-7p47-pfv8CVE-2026-29057
März 2026

Next.js: HTTP request smuggling in rewrites

Betroffen: >= 16.0.0-beta.0, < 16.1.7 · >= 9.5.0, < 15.5.13Behoben in 16.1.7, 15.5.13
mediumGHSA-3x4c-7xq6-9pq8CVE-2026-27980
März 2026

Next.js: Unbounded next/image disk cache growth can exhaust storage

Betroffen: >= 16.0.0-beta.0, < 16.1.7 · >= 10.0.0, < 15.5.14Behoben in 16.1.7, 15.5.14
mediumGHSA-h27x-g6w4-24gqCVE-2026-27979
März 2026

Next.js: Unbounded postponed resume buffering can lead to DoS

Betroffen: >= 16.0.1, < 16.1.7Behoben in 16.1.7
mediumGHSA-mq59-m269-xvcxCVE-2026-27978
März 2026

Next.js: null origin can bypass Server Actions CSRF checks

Betroffen: >= 16.0.1, < 16.1.7Behoben in 16.1.7
lowGHSA-jcc7-9wpm-mj36CVE-2026-27977
März 2026

Next.js: null origin can bypass dev HMR websocket CSRF checks

Betroffen: >= 16.0.1, < 16.1.7Behoben in 16.1.7
Jan. 2026

Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

Betroffen: >= 13.0.0, < 15.0.8 · >= 15.1.1-canary.0, < 15.1.12 · >= 15.2.0-canary.0, < 15.2.9 · >= 15.3.0-canary.0, < 15.3.9 · >= 15.4.0-canary.0, < 15.4.11 · >= 15.5.1-canary.0, < 15.5.10 · >= 15.6.0-canary.0, < 15.6.0-canary.61 · >= 16.0.0-beta.0, < 16.0.11 · >= 16.1.0-canary.0, < 16.1.5Behoben in 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5
mediumGHSA-5f7q-jpqc-wp7hCVE-2025-59472
Jan. 2026

Next.js has Unbounded Memory Consumption via PPR Resume Endpoint

Betroffen: >= 16.0.0-beta.0, < 16.1.5 · >= 15.6.0-canary.0, < 15.6.0-canary.61 · >= 15.0.0-canary.0, <= 15.0.0-canary.205 · >= 15.0.1-canary.0, <= 15.0.1-canary.3 · >= 15.0.2-canary.0, <= 15.0.2-canary.11 · >= 15.0.3-canary.0, <= 15.0.3-canary.9 · >= 15.0.4-canary.0, <= 15.0.4-canary.52 · >= 15.1.1-canary.0, <= 15.1.1-canary.27 · >= 15.2.0-canary.0, <= 15.2.0-canary.77 · >= 15.2.1-canary.0, <= 15.2.1-canary.6 · >= 15.2.2-canary.0, <= 15.2.2-canary.7 · >= 15.3.0-canary.0, <= 15.3.0-canary.46 · >= 15.3.1-canary.0, <= 15.3.1-canary.15 · >= 15.4.0-canary.0, <= 15.4.0-canary.130 · >= 15.4.2-canary.0, <= 15.4.2-canary.56 · >= 15.5.1-canary.0, <= 15.5.1-canary.39Behoben in 16.1.5, 15.6.0-canary.61
mediumGHSA-9g9p-9gw9-jx7fCVE-2025-59471
Jan. 2026

Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

Betroffen: >= 10.0.0, < 15.5.10 · >= 15.6.0-canary.0, < 16.1.5Behoben in 15.5.10, 16.1.5
Dez. 2025

Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

Betroffen: >= 13.3.1-canary.0, < 14.2.35 · >= 15.0.6, < 15.0.7 · >= 15.1.10, < 15.1.11 · >= 15.2.7, < 15.2.8 · >= 15.3.7, < 15.3.8 · >= 15.4.9, < 15.4.10 · >= 15.5.8, < 15.5.9 · >= 15.6.0-canary.59, < 15.6.0-canary.60 · >= 16.0.9, < 16.0.10 · >= 16.1.0-canary.17, < 16.1.0-canary.19Behoben in 14.2.35, 15.0.7, 15.1.11, 15.2.8, 15.3.8, 15.4.10, 15.5.9, 15.6.0-canary.60, 16.0.10, 16.1.0-canary.19
Dez. 2025

Next Server Actions Source Code Exposure

Betroffen: >= 15.0.0-canary.0, < 15.0.6 · >= 15.1.1-canary.0, < 15.1.10 · >= 15.2.0-canary.0, < 15.2.7 · >= 15.3.0-canary.0, < 15.3.7 · >= 15.4.0-canary.0, < 15.4.9 · >= 15.5.1-canary.0, < 15.5.8 · >= 15.6.0-canary.0, < 15.6.0-canary.59 · >= 16.0.0-beta.0, < 16.0.9 · >= 16.1.0-canary.0, < 16.1.0-canary.17Behoben in 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17
Dez. 2025

Next Vulnerable to Denial of Service with Server Components

Betroffen: >= 13.3.0, < 14.2.34 · >= 15.0.0-canary.0, < 15.0.6 · >= 15.1.1-canary.0, < 15.1.10 · >= 15.2.0-canary.0, < 15.2.7 · >= 15.3.0-canary.0, < 15.3.7 · >= 15.4.0-canary.0, < 15.4.9 · >= 15.5.1-canary.0, < 15.5.8 · >= 15.6.0-canary.0, < 15.6.0-canary.59 · >= 16.0.0-beta.0, < 16.0.9 · >= 16.1.0-canary.0, < 16.1.0-canary.17Behoben in 14.2.34, 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17
Dez. 2025

Next.js is vulnerable to RCE in React flight protocol

Betroffen: >= 14.3.0-canary.77, < 15.0.5 · >= 15.2.0-canary.0, < 15.2.6 · >= 15.3.0-canary.0, < 15.3.6 · >= 15.4.0-canary.0, < 15.4.8 · >= 16.0.0-canary.0, < 16.0.7 · >= 15.1.0-canary.0, < 15.1.9 · >= 15.5.0-canary.0, < 15.5.7Behoben in 15.0.5, 15.2.6, 15.3.6, 15.4.8, 16.0.7, 15.1.9, 15.5.7
mediumGHSA-g5qg-72qw-gw5vCVE-2025-57752
Aug. 2025

Next.js Affected by Cache Key Confusion for Image Optimization API Routes

Betroffen: >= 15.0.0, <= 15.4.4 · >= 0.9.9, < 14.2.31Behoben in 15.4.5, 14.2.31
mediumGHSA-xv57-4mr9-wg8vCVE-2025-55173
Aug. 2025

Next.js Content Injection Vulnerability for Image Optimization

Betroffen: >= 15.0.0, <= 15.4.4 · >= 0.9.9, < 14.2.31Behoben in 15.4.5, 14.2.31
mediumGHSA-4342-x723-ch2fCVE-2025-57822
Aug. 2025

Next.js Improper Middleware Redirect Handling Leads to SSRF

Betroffen: >= 15.0.0-canary.0, < 15.4.7 · >= 0.9.9, < 14.2.32Behoben in 15.4.7, 14.2.32
highGHSA-67rr-84xm-4c7rCVE-2025-49826
Juli 2025

Next.JS vulnerability can lead to DoS via cache poisoning

Betroffen: >= 15.0.4-canary.51, < 15.1.8Behoben in 15.1.8
lowGHSA-r2fc-ccr8-96c4CVE-2025-49005
Juli 2025

Next.js has a Cache poisoning vulnerability due to omission of the Vary header

Betroffen: >= 15.3.0, < 15.3.3Behoben in 15.3.3
lowGHSA-3h52-269p-cp9rCVE-2025-48068
Mai 2025

Information exposure in Next.js dev server due to lack of origin verification

Betroffen: >= 15.0.0, < 15.2.2 · >= 13.0, < 14.2.30Behoben in 15.2.2, 14.2.30
lowGHSA-qpjv-v59x-3qc4CVE-2025-32421
Mai 2025

Next.js Race Condition to Cache Poisoning

Betroffen: >= 15.0.0, < 15.1.6 · >= 0.9.9, < 14.2.24Behoben in 15.1.6, 14.2.24
lowGHSA-223j-4rm8-mrmfCVE-2025-30218
Apr. 2025

Next.js may leak x-middleware-subrequest-id to external hosts

Betroffen: = 12.3.5 · = 13.5.9 · = 14.2.25 · = 15.2.3Behoben in 12.3.6, 13.5.10, 14.2.26, 15.2.4
criticalGHSA-f82v-jwr5-mffwCVE-2025-29927
März 2025

Authorization Bypass in Next.js Middleware

Betroffen: >= 13.0.0, < 13.5.9 · >= 14.0.0, < 14.2.25 · >= 15.0.0, < 15.2.3 · >= 12.0.0, < 12.3.5Behoben in 13.5.9, 14.2.25, 15.2.3, 12.3.5
mediumGHSA-7m27-7ghc-44w9CVE-2024-56332
Jan. 2025

Next.js Allows a Denial of Service (DoS) with Server Actions

Betroffen: >= 13.0.0, < 13.5.8 · >= 14.0.0, < 14.2.21 · >= 15.0.0, < 15.1.2Behoben in 13.5.8, 14.2.21, 15.1.2
highGHSA-7gfc-8cq8-jh5fCVE-2024-51479
Dez. 2024

Next.js authorization bypass vulnerability

Betroffen: >= 9.5.5, < 14.2.15Behoben in 14.2.15
mediumGHSA-g77x-44xx-532mCVE-2024-47831
Okt. 2024

Denial of Service condition in Next.js image optimization

Betroffen: >= 10.0.0, < 14.2.7Behoben in 14.2.7
highGHSA-gp8f-8m3g-qvj9CVE-2024-46982
Sept. 2024

Next.js Cache Poisoning

Betroffen: >= 13.5.1, < 13.5.7 · >= 14.0.0, < 14.2.10Behoben in 13.5.7, 14.2.10
highGHSA-fq54-2j52-jc42CVE-2024-39693
Juli 2024

Next.js Denial of Service (DoS) condition

Betroffen: >= 13.3.1, < 13.5.0Behoben in 13.5.0
highGHSA-fr5h-rqp8-mj6gCVE-2024-34351
Mai 2024

Next.js Server-Side Request Forgery in Server Actions

Betroffen: >= 13.4.0, < 14.1.1Behoben in 14.1.1
highGHSA-77r5-gw3j-2mpfCVE-2024-34350
Mai 2024

Next.js Vulnerable to HTTP Request Smuggling

Betroffen: >= 13.4.0, < 13.5.1Behoben in 13.5.1
lowGHSA-c59h-r6p8-q9wcCVE-2023-46298
Okt. 2023

Next.js missing cache-control header may lead to CDN caching empty reply

Betroffen: >= 0.9.9, < 13.4.20-canary.13Behoben in 13.4.20-canary.13
mediumGHSA-wff4-fpwg-qqv3CVE-2022-36046
Aug. 2022

Unexpected server crash in Next.js

Betroffen: = 12.2.3Behoben in 12.2.4
mediumGHSA-fmvm-x8mv-47mjCVE-2022-23646
Feb. 2022

Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.1.0

Betroffen: >= 10.0.0, < 12.1.0Behoben in 12.1.0
mediumGHSA-wr66-vrwm-5g5xCVE-2022-21721
Jan. 2022

Denial of Service Vulnerability in next.js

Betroffen: >= 12.0.0, < 12.0.9Behoben in 12.0.9
highGHSA-25mp-g6fv-mqxxCVE-2021-43803
Dez. 2021

Unexpected server crash in Next.js.

Betroffen: >= 12.0.0, < 12.0.5 · >= 0.9.9, < 11.1.3Behoben in 12.0.5, 11.1.3
highGHSA-9gr3-7897-pp7mCVE-2021-39178
Sept. 2021

XSS in Image Optimization API for Next.js

Betroffen: >= 10.0.0, < 11.1.1Behoben in 11.1.1
mediumGHSA-vxf5-wxwp-m7g9CVE-2021-37699
Aug. 2021

Open Redirect in Next.js

Betroffen: >= 0.9.9, < 11.1.0Behoben in 11.1.0
mediumGHSA-x56p-c8cg-q435CVE-2020-15242
Okt. 2020

Open Redirect in Next.js versions

Betroffen: >= 9.5.0, < 9.5.4Behoben in 9.5.4
Sept. 2020

Remote Code Execution in next

Betroffen: >= 0.9.9, < 5.1.0Behoben in 5.1.0
mediumGHSA-fq77-7p7r-83rjCVE-2020-5284
März 2020

Directory Traversal in Next.js

Betroffen: >= 0.9.9, < 9.3.2Behoben in 9.3.2
mediumGHSA-qw96-mm2g-c8m7CVE-2018-18282
Okt. 2018

Next.js has cross site scripting (XSS) vulnerability via the 404 or 500 /_error page

Betroffen: >= 7.0.0, < 7.0.2Behoben in 7.0.2
highGHSA-m34x-wgrh-g897CVE-2018-6184
Jan. 2018

Directory traversal vulnerability in Next.js

Betroffen: >= 1.0.0, < 4.2.3Behoben in 4.2.3
highGHSA-3f5c-4qxj-vmpfCVE-2017-16877
Dez. 2017

Next.js Directory Traversal Vulnerability

Betroffen: >= 1.0.0, < 2.4.1Behoben in 2.4.1