Next.js security incidents
Recent advisories touching Next.js apps — searchable, enriched with exploit probability and affected versions.
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Next.js: Cache confusion of response bodies for requests with bodies
Next.js: Cache confusion of response bodies for requests with bodies
Next.js: Server-Side Request Forgery in Server Actions on custom servers
Next.js: Server-Side Request Forgery in Server Actions on custom servers
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Next.js: Denial of Service in App Router using Server Actions
Next.js: Denial of Service in App Router using Server Actions
Next.js: Unbounded Server Action payload in Edge runtime
Next.js: Unbounded Server Action payload in Edge runtime
Next.js: Denial of Service in the Image Optimization API using SVGs
Next.js: Denial of Service in the Image Optimization API using SVGs
Next.js: Unauthenticated disclosure of internal Server Function endpoints
Next.js: Unauthenticated disclosure of internal Server Function endpoints
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
Next.js has a Middleware / Proxy bypass through dynamic route parameter injection
Next.js has a Middleware / Proxy bypass through dynamic route parameter injection
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components
Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
Next.js Vulnerable to Denial of Service with Server Components
Next.js Vulnerable to Denial of Service with Server Components
Next.js's Middleware / Proxy redirects can be cache-poisoned
Next.js's Middleware / Proxy redirects can be cache-poisoned
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Next.js vulnerable to cache poisoning in React Server Component responses
Next.js vulnerable to cache poisoning in React Server Component responses
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
Next.js has a Denial of Service in the Image Optimization API
Next.js has a Denial of Service in the Image Optimization API
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
Next.js has a Denial of Service with Server Components
Next.js has a Denial of Service with Server Components
Next.js: HTTP request smuggling in rewrites
Next.js: HTTP request smuggling in rewrites
Next.js: Unbounded next/image disk cache growth can exhaust storage
Next.js: Unbounded next/image disk cache growth can exhaust storage
Next.js has Unbounded Memory Consumption via PPR Resume Endpoint
Next.js has Unbounded Memory Consumption via PPR Resume Endpoint
Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
Next.js is vulnerable to RCE in React flight protocol
Next.js is vulnerable to RCE in React flight protocol
Next.js Content Injection Vulnerability for Image Optimization
Next.js Content Injection Vulnerability for Image Optimization
Next.js Affected by Cache Key Confusion for Image Optimization API Routes
Next.js Affected by Cache Key Confusion for Image Optimization API Routes
Next.js Improper Middleware Redirect Handling Leads to SSRF
Next.js Improper Middleware Redirect Handling Leads to SSRF
Next.js has a Cache poisoning vulnerability due to omission of the Vary header
Next.js has a Cache poisoning vulnerability due to omission of the Vary header
Information exposure in Next.js dev server due to lack of origin verification
Information exposure in Next.js dev server due to lack of origin verification
next: 13.0 → 14.2.30
Authorization Bypass in Next.js Middleware
Authorization Bypass in Next.js Middleware
Next.js Allows a Denial of Service (DoS) with Server Actions
Next.js Allows a Denial of Service (DoS) with Server Actions
Denial of Service condition in Next.js image optimization
Denial of Service condition in Next.js image optimization
Next.js Cache Poisoning
Next.js Cache Poisoning
Next.js Denial of Service (DoS) condition
Next.js Denial of Service (DoS) condition
Next.js Vulnerable to HTTP Request Smuggling
Next.js Vulnerable to HTTP Request Smuggling
Next.js Server-Side Request Forgery in Server Actions
Next.js Server-Side Request Forgery in Server Actions
Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint
Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint
Denial of Service Vulnerability in next.js
Denial of Service Vulnerability in next.js
Open Redirect in Next.js versions
Open Redirect in Next.js versions
Directory Traversal in Next.js
Directory Traversal in Next.js
Tooling for Next.js
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.