66 Total advisories
66 Vulnerabilities
0 Malware

Dependency scanning

Check whether next is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.5
npm

CVE-2024-34351

Next.js Server-Side Request Forgery in Server Actions

UNKNOWN
npm

CVE-2025-48068

Information exposure in Next.js dev server due to lack of origin verification

MEDIUM 5.9
npm

CVE-2022-21721

Denial of Service Vulnerability in next.js

MEDIUM 4.7
npm

CVE-2020-15242

Open Redirect in Next.js versions

MEDIUM 4.4
npm

CVE-2020-5284

Directory Traversal in Next.js

UNKNOWN
npm

GHSA-2xp9-vwfh-vxw4

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

CRITICAL 9.0
npm

CVE-2026-75604

Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

CRITICAL 10.0
npm

GHSA-9qr9-h5gf-34mp

Next.js is vulnerable to RCE in React flight protocol

UNKNOWN
npm

CVE-2026-64647

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

UNKNOWN
npm

CVE-2026-64649

Next.js: Server-Side Request Forgery in Server Actions on custom servers

UNKNOWN
npm

CVE-2026-64644

Next.js: Denial of Service in the Image Optimization API using SVGs

UNKNOWN
npm

CVE-2026-64645

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

UNKNOWN
npm

CVE-2026-64648

Next.js: Cache confusion of response bodies for requests with bodies

UNKNOWN
npm

CVE-2026-64646

Next.js: Unbounded Server Action payload in Edge runtime

UNKNOWN
npm

CVE-2026-64643

Next.js: Unauthenticated disclosure of internal Server Function endpoints

UNKNOWN
npm

CVE-2026-64642

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

UNKNOWN
npm

CVE-2026-64641

Next.js: Denial of Service in App Router using Server Actions

MEDIUM 5.3
npm

CVE-2022-36046

Unexpected server crash in Next.js

HIGH 7.5
npm

CVE-2021-43803

Unexpected server crash in Next.js.

HIGH 7.5
npm

CVE-2021-39178

XSS in Image Optimization API for Next.js

MEDIUM 6.9
npm

CVE-2021-37699

Open Redirect in Next.js

MEDIUM 5.4
npm

CVE-2026-44576

Next.js vulnerable to cache poisoning in React Server Component responses

LOW 3.7
npm

CVE-2026-44582

Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

MEDIUM 5.9
npm

CVE-2026-44577

Next.js has a Denial of Service in the Image Optimization API

MEDIUM 6.1
npm

CVE-2026-44580

Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

MEDIUM 4.7
npm

CVE-2026-44581

Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces

HIGH 7.5
npm

CVE-2026-44579

Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components

HIGH 8.6
npm

CVE-2026-44578

Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades

LOW 3.7
npm

CVE-2026-44572

Next.js's Middleware / Proxy redirects can be cache-poisoned

HIGH 7.5
npm

CVE-2026-44573

Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n

HIGH 7.5
npm

CVE-2026-44575

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes

HIGH 8.1
npm

CVE-2026-44574

Next.js has a Middleware / Proxy bypass through dynamic route parameter injection

HIGH 7.5
npm

CVE-2026-45109

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up

HIGH 7.5
npm

GHSA-8h8q-6873-q5fj

Next.js Vulnerable to Denial of Service with Server Components

HIGH 7.5
npm

GHSA-q4gf-8mx6-v5v3

Next.js has a Denial of Service with Server Components

MEDIUM 5.9
npm

CVE-2025-59472

Next.js has Unbounded Memory Consumption via PPR Resume Endpoint

UNKNOWN
npm

CVE-2026-27977

Next.js: null origin can bypass dev HMR websocket CSRF checks

UNKNOWN
npm

CVE-2026-27980

Next.js: Unbounded next/image disk cache growth can exhaust storage

UNKNOWN
npm

CVE-2026-27979

Next.js: Unbounded postponed resume buffering can lead to DoS

UNKNOWN
npm

CVE-2026-27978

Next.js: null origin can bypass Server Actions CSRF checks

UNKNOWN
npm

CVE-2026-29057

Next.js: HTTP request smuggling in rewrites

CRITICAL 9.1
npm

CVE-2025-29927

Authorization Bypass in Next.js Middleware

HIGH 7.5
npm

GHSA-h25m-26qc-wcjf

Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

MEDIUM 5.9
npm

CVE-2025-59471

Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

MEDIUM 5.3
npm

CVE-2024-56332

Next.js Allows a Denial of Service (DoS) with Server Actions

MEDIUM 4.3
npm

CVE-2025-55173

Next.js Content Injection Vulnerability for Image Optimization

MEDIUM 6.5
npm

CVE-2025-57822

Next.js Improper Middleware Redirect Handling Leads to SSRF

HIGH 7.5
npm

GHSA-mwv6-3258-q52c

Next Vulnerable to Denial of Service with Server Components

HIGH 7.5
npm

CVE-2024-46982

Next.js Cache Poisoning

MEDIUM 5.9
npm

CVE-2024-47831

Denial of Service condition in Next.js image optimization

MEDIUM 5.3
npm

GHSA-w37m-7fhw-fmv9

Next Server Actions Source Code Exposure

MEDIUM 6.2
npm

CVE-2025-57752

Next.js Affected by Cache Key Confusion for Image Optimization API Routes

HIGH 7.5
npm

GHSA-5j59-xgg2-r9c4

Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

LOW 3.7
npm

CVE-2025-49005

Next.js has a Cache poisoning vulnerability due to omission of the Vary header

UNKNOWN
npm

CVE-2025-30218

Next.js may leak x-middleware-subrequest-id to external hosts

LOW 3.7
npm

CVE-2025-32421

Next.js Race Condition to Cache Poisoning

HIGH 7.5
npm

CVE-2024-51479

Next.js authorization bypass vulnerability

HIGH 7.5
npm

CVE-2025-49826

Next.JS vulnerability can lead to DoS via cache poisoning

HIGH 7.5
npm

CVE-2024-39693

Next.js Denial of Service (DoS) condition

HIGH 7.5
npm

CVE-2024-34350

Next.js Vulnerable to HTTP Request Smuggling

HIGH 7.5
npm

CVE-2017-16877

Next.js Directory Traversal Vulnerability

UNKNOWN
npm

CVE-2023-46298

Next.js missing cache-control header may lead to CDN caching empty reply

MEDIUM 5.9
npm

CVE-2022-23646

Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.1.0

HIGH 7.5
npm

CVE-2018-6184

Directory traversal vulnerability in Next.js

MEDIUM 6.1
npm

CVE-2018-18282

Next.js has cross site scripting (XSS) vulnerability via the 404 or 500 /_error page

UNKNOWN
npm

GHSA-5vj8-3v2h-h38v

Remote Code Execution in next

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes