Next.js security incidents

Recent advisories touching Next.js apps — searchable, enriched with exploit probability and affected versions.

CRITICALnpm

Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

4 days ago
CRITICALnpm

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

4 days ago
MODERATEnpm

Next.js: Cache confusion of response bodies for requests with bodies

Next.js: Cache confusion of response bodies for requests with bodies

1 month ago
HIGHnpm

Next.js: Server-Side Request Forgery in Server Actions on custom servers

Next.js: Server-Side Request Forgery in Server Actions on custom servers

1 month ago
MODERATEnpm

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

1 month ago
HIGHnpm

Next.js: Denial of Service in App Router using Server Actions

Next.js: Denial of Service in App Router using Server Actions

1 month ago
MODERATEnpm

Next.js: Unbounded Server Action payload in Edge runtime

Next.js: Unbounded Server Action payload in Edge runtime

1 month ago
MODERATEnpm

Next.js: Denial of Service in the Image Optimization API using SVGs

Next.js: Denial of Service in the Image Optimization API using SVGs

1 month ago
MODERATEnpm

Next.js: Unauthenticated disclosure of internal Server Function endpoints

Next.js: Unauthenticated disclosure of internal Server Function endpoints

1 month ago
HIGHnpm

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

1 month ago
HIGHnpm

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

1 month ago
HIGHnpm

Next.js has a Middleware / Proxy bypass through dynamic route parameter injection

Next.js has a Middleware / Proxy bypass through dynamic route parameter injection

4 months ago
MEDIUMnpm

Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces

Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces

4 months ago
HIGHnpm

Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n

Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n

4 months ago
HIGHnpm

Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components

Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components

4 months ago
MEDIUMnpm

Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

4 months ago
HIGHnpm

Next.js Vulnerable to Denial of Service with Server Components

Next.js Vulnerable to Denial of Service with Server Components

4 months ago
MEDIUMnpm

Next.js's Middleware / Proxy redirects can be cache-poisoned

Next.js's Middleware / Proxy redirects can be cache-poisoned

4 months ago
HIGHnpm

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes

4 months ago
MEDIUMnpm

Next.js vulnerable to cache poisoning in React Server Component responses

Next.js vulnerable to cache poisoning in React Server Component responses

4 months ago
MEDIUMnpm

Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

4 months ago
HIGHnpm

Next.js has a Denial of Service in the Image Optimization API

Next.js has a Denial of Service in the Image Optimization API

4 months ago
HIGHnpm

Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades

Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades

4 months ago
HIGHnpm

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up

4 months ago
HIGHnpm

Next.js has a Denial of Service with Server Components

Next.js has a Denial of Service with Server Components

5 months ago
MODERATEnpm

Next.js: HTTP request smuggling in rewrites

Next.js: HTTP request smuggling in rewrites

5 months ago
MODERATEnpm

Next.js: Unbounded next/image disk cache growth can exhaust storage

Next.js: Unbounded next/image disk cache growth can exhaust storage

5 months ago
HIGHnpm

Next.js has Unbounded Memory Consumption via PPR Resume Endpoint

Next.js has Unbounded Memory Consumption via PPR Resume Endpoint

7 months ago
HIGHnpm

Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

7 months ago
HIGHnpm

Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

7 months ago
CRITICALnpm

Next.js is vulnerable to RCE in React flight protocol

Next.js is vulnerable to RCE in React flight protocol

9 months ago
MEDIUMnpm

Next.js Content Injection Vulnerability for Image Optimization

Next.js Content Injection Vulnerability for Image Optimization

1 year ago
HIGHnpm

Next.js Affected by Cache Key Confusion for Image Optimization API Routes

Next.js Affected by Cache Key Confusion for Image Optimization API Routes

1 year ago
HIGHnpm

Next.js Improper Middleware Redirect Handling Leads to SSRF

Next.js Improper Middleware Redirect Handling Leads to SSRF

1 year ago
MEDIUMnpm

Next.js has a Cache poisoning vulnerability due to omission of the Vary header

Next.js has a Cache poisoning vulnerability due to omission of the Vary header

1 year ago
LOWnpm

Information exposure in Next.js dev server due to lack of origin verification

Information exposure in Next.js dev server due to lack of origin verification

next: 13.0 → 14.2.30

1 year ago
HIGHnpm

Authorization Bypass in Next.js Middleware

Authorization Bypass in Next.js Middleware

1 year ago
MEDIUMnpm

Next.js Allows a Denial of Service (DoS) with Server Actions

Next.js Allows a Denial of Service (DoS) with Server Actions

1 year ago
HIGHnpm

Denial of Service condition in Next.js image optimization

Denial of Service condition in Next.js image optimization

1 year ago
HIGHnpm

Next.js Cache Poisoning

Next.js Cache Poisoning

1 year ago
HIGHnpm

Next.js Denial of Service (DoS) condition

Next.js Denial of Service (DoS) condition

2 years ago
HIGHnpm

Next.js Vulnerable to HTTP Request Smuggling

Next.js Vulnerable to HTTP Request Smuggling

2 years ago
HIGHnpm

Next.js Server-Side Request Forgery in Server Actions

Next.js Server-Side Request Forgery in Server Actions

2 years ago
MEDIUMnpm

Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint

Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint

2 years ago
HIGHnpm

Denial of Service Vulnerability in next.js

Denial of Service Vulnerability in next.js

4 years ago
MEDIUMnpm

Open Redirect in Next.js versions

Open Redirect in Next.js versions

5 years ago
MEDIUMnpm

Directory Traversal in Next.js

Directory Traversal in Next.js

6 years ago

Tooling for Next.js

VercelShip a patched app with zero-config deployment.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.