Next.js: Denial of Service in App Router using Server Actions
Affected: >= 13.0.0, < 15.5.21 · >= 16.0.0, < 16.2.11Fixed in 15.5.21, 16.2.11
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
Affected: >= 15.2.0, < 15.5.18 · >= 16.0.0, < 16.2.6Fixed in 15.5.18, 16.2.6
Next.js's Middleware / Proxy redirects can be cache-poisoned
Affected: >= 12.2.0, < 15.5.16 · >= 16.0.0, < 16.2.5Fixed in 15.5.16, 16.2.5
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
Affected: >= 13.4.0, < 15.5.16 · >= 16.0.0, < 16.2.5Fixed in 15.5.16, 16.2.5
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
Affected: >= 13.4.6, < 15.5.16 · >= 16.0.0, < 16.2.5Fixed in 15.5.16, 16.2.5
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
Affected: >= 13.0.0, < 15.5.16 · >= 16.0.0, < 16.2.5Fixed in 15.5.16, 16.2.5
Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components
Affected: >= 15.0.0, < 15.5.16 · >= 16.0.0, < 16.2.5Fixed in 15.5.16, 16.2.5
Next.js has a Denial of Service in the Image Optimization API
Affected: >= 10.0.0, < 15.5.16 · >= 16.0.0, < 16.2.5Fixed in 15.5.16, 16.2.5
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
Affected: >= 13.4.13, < 15.5.16 · >= 16.0.0, < 16.2.5Fixed in 15.5.16, 16.2.5
Next.js vulnerable to cache poisoning in React Server Component responses
Affected: >= 14.2.0, < 15.5.16 · >= 16.0.0, < 16.2.5Fixed in 15.5.16, 16.2.5
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Affected: >= 15.2.0, < 15.5.16 · >= 16.0.0, < 16.2.5Fixed in 15.5.16, 16.2.5
Next.js has a Middleware / Proxy bypass through dynamic route parameter injection
Affected: >= 15.4.0, < 15.5.16 · >= 16.0.0, < 16.2.5Fixed in 15.5.16, 16.2.5
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
Affected: >= 12.2.0, < 15.5.16 · >= 16.0.0, < 16.2.5Fixed in 15.5.16, 16.2.5
Next.js Vulnerable to Denial of Service with Server Components
Affected: >= 13.0.0, < 15.5.16 · >= 16.0.0, < 16.2.5Fixed in 15.5.16, 16.2.5
Next.js has a Denial of Service with Server Components
Affected: >= 13.0.0, < 15.5.15 · >= 16.0.0-beta.0, < 16.2.3Fixed in 15.5.15, 16.2.3
Next.js: HTTP request smuggling in rewrites
Affected: >= 16.0.0-beta.0, < 16.1.7 · >= 9.5.0, < 15.5.13Fixed in 16.1.7, 15.5.13
Next.js: Unbounded next/image disk cache growth can exhaust storage
Affected: >= 16.0.0-beta.0, < 16.1.7 · >= 10.0.0, < 15.5.14Fixed in 16.1.7, 15.5.14
Next.js: Unbounded postponed resume buffering can lead to DoS
Affected: >= 16.0.1, < 16.1.7Fixed in 16.1.7
Next.js: null origin can bypass Server Actions CSRF checks
Affected: >= 16.0.1, < 16.1.7Fixed in 16.1.7
Next.js: null origin can bypass dev HMR websocket CSRF checks
Affected: >= 16.0.1, < 16.1.7Fixed in 16.1.7
Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
Affected: >= 13.0.0, < 15.0.8 · >= 15.1.1-canary.0, < 15.1.12 · >= 15.2.0-canary.0, < 15.2.9 · >= 15.3.0-canary.0, < 15.3.9 · >= 15.4.0-canary.0, < 15.4.11 · >= 15.5.1-canary.0, < 15.5.10 · >= 15.6.0-canary.0, < 15.6.0-canary.61 · >= 16.0.0-beta.0, < 16.0.11 · >= 16.1.0-canary.0, < 16.1.5Fixed in 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5
Next.js has Unbounded Memory Consumption via PPR Resume Endpoint
Affected: >= 16.0.0-beta.0, < 16.1.5 · >= 15.6.0-canary.0, < 15.6.0-canary.61 · >= 15.0.0-canary.0, <= 15.0.0-canary.205 · >= 15.0.1-canary.0, <= 15.0.1-canary.3 · >= 15.0.2-canary.0, <= 15.0.2-canary.11 · >= 15.0.3-canary.0, <= 15.0.3-canary.9 · >= 15.0.4-canary.0, <= 15.0.4-canary.52 · >= 15.1.1-canary.0, <= 15.1.1-canary.27 · >= 15.2.0-canary.0, <= 15.2.0-canary.77 · >= 15.2.1-canary.0, <= 15.2.1-canary.6 · >= 15.2.2-canary.0, <= 15.2.2-canary.7 · >= 15.3.0-canary.0, <= 15.3.0-canary.46 · >= 15.3.1-canary.0, <= 15.3.1-canary.15 · >= 15.4.0-canary.0, <= 15.4.0-canary.130 · >= 15.4.2-canary.0, <= 15.4.2-canary.56 · >= 15.5.1-canary.0, <= 15.5.1-canary.39Fixed in 16.1.5, 15.6.0-canary.61
Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
Affected: >= 10.0.0, < 15.5.10 · >= 15.6.0-canary.0, < 16.1.5Fixed in 15.5.10, 16.1.5
Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
Affected: >= 13.3.1-canary.0, < 14.2.35 · >= 15.0.6, < 15.0.7 · >= 15.1.10, < 15.1.11 · >= 15.2.7, < 15.2.8 · >= 15.3.7, < 15.3.8 · >= 15.4.9, < 15.4.10 · >= 15.5.8, < 15.5.9 · >= 15.6.0-canary.59, < 15.6.0-canary.60 · >= 16.0.9, < 16.0.10 · >= 16.1.0-canary.17, < 16.1.0-canary.19Fixed in 14.2.35, 15.0.7, 15.1.11, 15.2.8, 15.3.8, 15.4.10, 15.5.9, 15.6.0-canary.60, 16.0.10, 16.1.0-canary.19
Next Server Actions Source Code Exposure
Affected: >= 15.0.0-canary.0, < 15.0.6 · >= 15.1.1-canary.0, < 15.1.10 · >= 15.2.0-canary.0, < 15.2.7 · >= 15.3.0-canary.0, < 15.3.7 · >= 15.4.0-canary.0, < 15.4.9 · >= 15.5.1-canary.0, < 15.5.8 · >= 15.6.0-canary.0, < 15.6.0-canary.59 · >= 16.0.0-beta.0, < 16.0.9 · >= 16.1.0-canary.0, < 16.1.0-canary.17Fixed in 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17
Next Vulnerable to Denial of Service with Server Components
Affected: >= 13.3.0, < 14.2.34 · >= 15.0.0-canary.0, < 15.0.6 · >= 15.1.1-canary.0, < 15.1.10 · >= 15.2.0-canary.0, < 15.2.7 · >= 15.3.0-canary.0, < 15.3.7 · >= 15.4.0-canary.0, < 15.4.9 · >= 15.5.1-canary.0, < 15.5.8 · >= 15.6.0-canary.0, < 15.6.0-canary.59 · >= 16.0.0-beta.0, < 16.0.9 · >= 16.1.0-canary.0, < 16.1.0-canary.17Fixed in 14.2.34, 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17
Next.js is vulnerable to RCE in React flight protocol
Affected: >= 14.3.0-canary.77, < 15.0.5 · >= 15.2.0-canary.0, < 15.2.6 · >= 15.3.0-canary.0, < 15.3.6 · >= 15.4.0-canary.0, < 15.4.8 · >= 16.0.0-canary.0, < 16.0.7 · >= 15.1.0-canary.0, < 15.1.9 · >= 15.5.0-canary.0, < 15.5.7Fixed in 15.0.5, 15.2.6, 15.3.6, 15.4.8, 16.0.7, 15.1.9, 15.5.7
Next.js Affected by Cache Key Confusion for Image Optimization API Routes
Affected: >= 15.0.0, <= 15.4.4 · >= 0.9.9, < 14.2.31Fixed in 15.4.5, 14.2.31
Next.js Content Injection Vulnerability for Image Optimization
Affected: >= 15.0.0, <= 15.4.4 · >= 0.9.9, < 14.2.31Fixed in 15.4.5, 14.2.31
Next.js Improper Middleware Redirect Handling Leads to SSRF
Affected: >= 15.0.0-canary.0, < 15.4.7 · >= 0.9.9, < 14.2.32Fixed in 15.4.7, 14.2.32
Next.JS vulnerability can lead to DoS via cache poisoning
Affected: >= 15.0.4-canary.51, < 15.1.8Fixed in 15.1.8
Next.js has a Cache poisoning vulnerability due to omission of the Vary header
Affected: >= 15.3.0, < 15.3.3Fixed in 15.3.3
Information exposure in Next.js dev server due to lack of origin verification
Affected: >= 15.0.0, < 15.2.2 · >= 13.0, < 14.2.30Fixed in 15.2.2, 14.2.30
Next.js Race Condition to Cache Poisoning
Affected: >= 15.0.0, < 15.1.6 · >= 0.9.9, < 14.2.24Fixed in 15.1.6, 14.2.24
Next.js may leak x-middleware-subrequest-id to external hosts
Affected: = 12.3.5 · = 13.5.9 · = 14.2.25 · = 15.2.3Fixed in 12.3.6, 13.5.10, 14.2.26, 15.2.4
Authorization Bypass in Next.js Middleware
Affected: >= 13.0.0, < 13.5.9 · >= 14.0.0, < 14.2.25 · >= 15.0.0, < 15.2.3 · >= 12.0.0, < 12.3.5Fixed in 13.5.9, 14.2.25, 15.2.3, 12.3.5
Next.js Allows a Denial of Service (DoS) with Server Actions
Affected: >= 13.0.0, < 13.5.8 · >= 14.0.0, < 14.2.21 · >= 15.0.0, < 15.1.2Fixed in 13.5.8, 14.2.21, 15.1.2
Next.js authorization bypass vulnerability
Affected: >= 9.5.5, < 14.2.15Fixed in 14.2.15
Denial of Service condition in Next.js image optimization
Affected: >= 10.0.0, < 14.2.7Fixed in 14.2.7
Next.js Cache Poisoning
Affected: >= 13.5.1, < 13.5.7 · >= 14.0.0, < 14.2.10Fixed in 13.5.7, 14.2.10
Next.js Denial of Service (DoS) condition
Affected: >= 13.3.1, < 13.5.0Fixed in 13.5.0
Next.js Server-Side Request Forgery in Server Actions
Affected: >= 13.4.0, < 14.1.1Fixed in 14.1.1
Next.js Vulnerable to HTTP Request Smuggling
Affected: >= 13.4.0, < 13.5.1Fixed in 13.5.1
Next.js missing cache-control header may lead to CDN caching empty reply
Affected: >= 0.9.9, < 13.4.20-canary.13Fixed in 13.4.20-canary.13
Unexpected server crash in Next.js
Affected: = 12.2.3Fixed in 12.2.4
Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.1.0
Affected: >= 10.0.0, < 12.1.0Fixed in 12.1.0
Denial of Service Vulnerability in next.js
Affected: >= 12.0.0, < 12.0.9Fixed in 12.0.9
Unexpected server crash in Next.js.
Affected: >= 12.0.0, < 12.0.5 · >= 0.9.9, < 11.1.3Fixed in 12.0.5, 11.1.3
XSS in Image Optimization API for Next.js
Affected: >= 10.0.0, < 11.1.1Fixed in 11.1.1
Open Redirect in Next.js
Affected: >= 0.9.9, < 11.1.0Fixed in 11.1.0
Open Redirect in Next.js versions
Affected: >= 9.5.0, < 9.5.4Fixed in 9.5.4
Remote Code Execution in next
Affected: >= 0.9.9, < 5.1.0Fixed in 5.1.0
Directory Traversal in Next.js
Affected: >= 0.9.9, < 9.3.2Fixed in 9.3.2
Next.js has cross site scripting (XSS) vulnerability via the 404 or 500 /_error page
Affected: >= 7.0.0, < 7.0.2Fixed in 7.0.2
Directory traversal vulnerability in Next.js
Affected: >= 1.0.0, < 4.2.3Fixed in 4.2.3
Next.js Directory Traversal Vulnerability
Affected: >= 1.0.0, < 2.4.1Fixed in 2.4.1