Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c39-4ccg-62r3

Опубликовано: 22 июл. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.3

Описание

Next.js: Unbounded Server Action payload in Edge runtime

Impact

Requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime

Workarounds

If you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.

Пакеты

Наименование

next

npm
Затронутые версииВерсия исправления

>= 13.0.0, < 15.5.21

15.5.21

Наименование

next

npm
Затронутые версииВерсия исправления

>= 16.0.0, < 16.2.11

16.2.11

EPSS

Процентиль: 42%
0.00531
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
redhat
5 дней назад

A flaw was found in Next.js. An attacker sending specially crafted requests to a Next.js application utilizing the App Router with Server Actions configured to use the Edge runtime can cause excessive memory consumption. This can lead to a denial of service (DoS) due to resource exhaustion.

CVSS3: 5.3
nvd
5 дней назад

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime. This issue has been fixed in versions 15.5.21 and 16.2.11.

EPSS

Процентиль: 42%
0.00531
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-770