next
npm56 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting nextpage 2 of 2
- CVE-2026-64644MEDIUMCVSS 5.3EG 5.3✓ Fixed in 16.2.112026-07-22
Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely…
- CVE-2026-64645MEDIUMCVSS 6.1EG 6.1✓ Fixed in 16.2.112026-07-22
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled i…
- CVE-2026-64646MEDIUMCVSS 5.3EG 5.3✓ Fixed in 16.2.112026-07-22
Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server Action can lead to exce…
- CVE-2026-64647MEDIUMCVSS 5.4EG 5.4✓ Fixed in 16.2.112026-07-22
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the…
- CVE-2026-64648MEDIUMCVSS 5.4EG 5.4✓ Fixed in 16.2.112026-07-22
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to th…
- CVE-2026-64649MEDIUMCVSS 6.5EG 6.5✓ Fixed in 16.2.112026-07-22
Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbo…
Check whether next is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for next CVEs against the assets you own.
Start Free Scan →