Next.js — открытый JavaScript фреймворк, созданный поверх React.js для создания веб-приложений
Релизный цикл, информация об уязвимостях
График релизов
Количество 191
GHSA-4633-3j49-mh5q
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
GHSA-4c39-4ccg-62r3
Next.js: Unbounded Server Action payload in Edge runtime
GHSA-p9j2-gv94-2wf4
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
GHSA-q8wf-6r8g-63ch
Next.js: Denial of Service in the Image Optimization API using SVGs
GHSA-955p-x3mx-jcvp
Next.js: Unauthenticated disclosure of internal Server Function endpoints
GHSA-6gpp-xcg3-4w24
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
GHSA-m99w-x7hq-7vfj
Next.js: Denial of Service in App Router using Server Actions
CVE-2026-45109
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.
CVE-2026-44582
Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.
CVE-2026-44581
Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed in 15.5.16 and 16.2.5.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-4633-3j49-mh5q Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences | 0% Низкий | около 2 месяцев назад | ||
GHSA-4c39-4ccg-62r3 Next.js: Unbounded Server Action payload in Edge runtime | 1% Низкий | около 2 месяцев назад | ||
GHSA-p9j2-gv94-2wf4 Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname | 1% Низкий | около 2 месяцев назад | ||
GHSA-q8wf-6r8g-63ch Next.js: Denial of Service in the Image Optimization API using SVGs | 1% Низкий | около 2 месяцев назад | ||
GHSA-955p-x3mx-jcvp Next.js: Unauthenticated disclosure of internal Server Function endpoints | 1% Низкий | около 2 месяцев назад | ||
GHSA-6gpp-xcg3-4w24 Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale | 1% Низкий | около 2 месяцев назад | ||
GHSA-m99w-x7hq-7vfj Next.js: Denial of Service in App Router using Server Actions | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-45109 Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-44582 Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5. | CVSS3: 3.7 | 0% Низкий | 4 месяца назад | |
CVE-2026-44581 Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed in 15.5.16 and 16.2.5. | CVSS3: 4.7 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу