Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Next.js

Next.jsоткрытый JavaScript фреймворк, созданный поверх React.js для создания веб-приложений

Релизный цикл, информация об уязвимостях

Продукт: Next.js
Вендор: vercel

График релизов

15162024202520262027

Недавние уязвимости Next.js

Количество 191

github логотип

GHSA-4633-3j49-mh5q

около 2 месяцев назад

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

EPSS: Низкий
github логотип

GHSA-4c39-4ccg-62r3

около 2 месяцев назад

Next.js: Unbounded Server Action payload in Edge runtime

EPSS: Низкий
github логотип

GHSA-p9j2-gv94-2wf4

около 2 месяцев назад

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

EPSS: Низкий
github логотип

GHSA-q8wf-6r8g-63ch

около 2 месяцев назад

Next.js: Denial of Service in the Image Optimization API using SVGs

EPSS: Низкий
github логотип

GHSA-955p-x3mx-jcvp

около 2 месяцев назад

Next.js: Unauthenticated disclosure of internal Server Function endpoints

EPSS: Низкий
github логотип

GHSA-6gpp-xcg3-4w24

около 2 месяцев назад

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

EPSS: Низкий
github логотип

GHSA-m99w-x7hq-7vfj

около 2 месяцев назад

Next.js: Denial of Service in App Router using Server Actions

EPSS: Низкий
nvd логотип

CVE-2026-45109

4 месяца назад

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-44582

4 месяца назад

Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2026-44581

4 месяца назад

Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed in 15.5.16 and 16.2.5.

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-4633-3j49-mh5q

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4c39-4ccg-62r3

Next.js: Unbounded Server Action payload in Edge runtime

1%
Низкий
около 2 месяцев назад
github логотип
GHSA-p9j2-gv94-2wf4

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

1%
Низкий
около 2 месяцев назад
github логотип
GHSA-q8wf-6r8g-63ch

Next.js: Denial of Service in the Image Optimization API using SVGs

1%
Низкий
около 2 месяцев назад
github логотип
GHSA-955p-x3mx-jcvp

Next.js: Unauthenticated disclosure of internal Server Function endpoints

1%
Низкий
около 2 месяцев назад
github логотип
GHSA-6gpp-xcg3-4w24

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

1%
Низкий
около 2 месяцев назад
github логотип
GHSA-m99w-x7hq-7vfj

Next.js: Denial of Service in App Router using Server Actions

1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-45109

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-44582

Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.

CVSS3: 3.7
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-44581

Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed in 15.5.16 and 16.2.5.

CVSS3: 4.7
0%
Низкий
4 месяца назад

Уязвимостей на страницу


Поделиться