next
npm61 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting nextpage 2 of 2
- CVE-2026-64644MEDIUMCVSS 5.3EG 5.3fixed in 15.5.21 or 16.2.11, by version range2026-07-22
Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely…
- CVE-2026-64645MEDIUMCVSS 6.1EG 6.1fixed in 15.5.21 or 16.2.11, by version range2026-07-22
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled i…
- CVE-2026-64646MEDIUMCVSS 5.3EG 5.3fixed in 15.5.21 or 16.2.11, by version range2026-07-22
Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server Action can lead to exce…
- CVE-2026-64647MEDIUMCVSS 5.4EG 5.4fixed in 15.5.21 or 16.2.11, by version range2026-07-22
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the…
- CVE-2026-64648MEDIUMCVSS 5.4EG 5.4fixed in 15.5.21 or 16.2.11, by version range2026-07-22
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to th…
- CVE-2026-64649MEDIUMCVSS 6.5EG 6.5fixed in 15.5.21 or 16.2.11, by version range2026-07-22
Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbo…
- CVE-2026-75604CRITICALCVSS 9.0EG 9.0fixed in 15.5.24 or 16.3.3, by version range2026-09-01
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escap…
- CVE-2026-94483MEDIUMCVSS 6.5EG 6.5fixed in 16.3.82026-10-02
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized i…
- CVE-2026-94484MEDIUMCVSS 4.8EG 4.8fixed in 16.3.8 or 15.5.27, by version range2026-10-02
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Static Regeneration routes can use a shared …
- CVE-2026-94543MEDIUMCVSS 5.3EG 5.3fixed in 15.5.27 or 16.3.8, by version range2026-10-02
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a respo…
- CVE-2026-94544MEDIUMCVSS 4.2EG 4.2fixed in 16.3.82026-10-02
Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular reque…
Check whether next is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for next CVEs against the assets you own.
Book a Demo →