Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44580

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vulnerability is fixed in 15.5.16 and 16.2.5.

A flaw was found in Next.js. A remote attacker could exploit this cross-site scripting (XSS) vulnerability by injecting untrusted content into beforeInteractive scripts. Due to improper escaping of serialized script content, this could allow the attacker to execute arbitrary JavaScript code in a visitor's browser, leading to information disclosure or unauthorized actions.

Отчет

This is a Moderate cross-site scripting (XSS) vulnerability affecting Next.js applications. The flaw occurs when applications employ beforeInteractive scripts with unsanitized, untrusted content, enabling remote attackers to execute arbitrary JavaScript. The requirement for this specific script strategy and attacker-controlled input limits the overall exposure in Red Hat deployments.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nodejs22Not affected
Red Hat Enterprise Linux 10nodejs24Not affected
Red Hat Enterprise Linux 8nodejs:22/nodejsNot affected
Red Hat Enterprise Linux 8nodejs:24/nodejsNot affected
Red Hat Enterprise Linux 9nodejs:22/nodejsNot affected
Red Hat Enterprise Linux 9nodejs:24/nodejsNot affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gaudi-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/disk-image-cuda-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2477186next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content

EPSS

Процентиль: 11%
0.00205
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
3 месяца назад

Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vulnerability is fixed in 15.5.16 and 16.2.5.

CVSS3: 6.1
github
3 месяца назад

Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

CVSS3: 6.1
fstec
3 месяца назад

Уязвимость функции beforeInteractive() программной платформы создания веб-приложений Next.js, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 11%
0.00205
Низкий

6.1 Medium

CVSS3