Next.js — открытый JavaScript фреймворк, созданный поверх React.js для создания веб-приложений
Релизный цикл, информация об уязвимостях
График релизов
Количество 160
GHSA-ffhc-5mcf-pf4q
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
GHSA-vfv6-92ff-j949
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
GHSA-gx5p-jg67-6x7h
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
GHSA-mg66-mrh9-m8jx
Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components
GHSA-h64f-5h5j-jqjh
Next.js has a Denial of Service in the Image Optimization API
GHSA-c4j6-fc7j-m34r
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
GHSA-wfc6-r584-vfw7
Next.js vulnerable to cache poisoning in React Server Component responses
GHSA-267c-6grr-h53f
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
GHSA-492v-c6pp-mqqv
Next.js has a Middleware / Proxy bypass through dynamic route parameter injection
GHSA-36qx-fr4f-26g5
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-ffhc-5mcf-pf4q Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces | CVSS3: 4.7 | 0% Низкий | 3 месяца назад | |
GHSA-vfv6-92ff-j949 Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
GHSA-gx5p-jg67-6x7h Next.js has cross-site scripting in beforeInteractive scripts with untrusted input | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
GHSA-mg66-mrh9-m8jx Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
GHSA-h64f-5h5j-jqjh Next.js has a Denial of Service in the Image Optimization API | CVSS3: 5.9 | 1% Низкий | 3 месяца назад | |
GHSA-c4j6-fc7j-m34r Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades | CVSS3: 8.6 | 39% Средний | 3 месяца назад | |
GHSA-wfc6-r584-vfw7 Next.js vulnerable to cache poisoning in React Server Component responses | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
GHSA-267c-6grr-h53f Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
GHSA-492v-c6pp-mqqv Next.js has a Middleware / Proxy bypass through dynamic route parameter injection | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
GHSA-36qx-fr4f-26g5 Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n | CVSS3: 7.5 | 1% Низкий | 3 месяца назад |
Уязвимостей на страницу