Vulnerabilities
CVE-2026-44576
Next.js vulnerable to cache poisoning in React Server Component responses
CVE-2026-44582
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
CVE-2026-44577
Next.js has a Denial of Service in the Image Optimization API
CVE-2026-44580
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
CVE-2026-44581
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
CVE-2026-44579
Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components
CVE-2026-44578
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
CVE-2026-44572
Next.js's Middleware / Proxy redirects can be cache-poisoned
CVE-2026-44573
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
CVE-2026-44575
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVE-2026-44574
Next.js has a Middleware / Proxy bypass through dynamic route parameter injection
CVE-2026-45109
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
GHSA-8h8q-6873-q5fj
Next.js Vulnerable to Denial of Service with Server Components
GHSA-q4gf-8mx6-v5v3
Next.js has a Denial of Service with Server Components
CVE-2025-59472
Next.js has Unbounded Memory Consumption via PPR Resume Endpoint
CVE-2026-27977
Next.js: null origin can bypass dev HMR websocket CSRF checks
CVE-2026-27980
Next.js: Unbounded next/image disk cache growth can exhaust storage
CVE-2026-27979
Next.js: Unbounded postponed resume buffering can lead to DoS
CVE-2026-27978
Next.js: null origin can bypass Server Actions CSRF checks
CVE-2026-29057
Next.js: HTTP request smuggling in rewrites
CVE-2020-15242
Open Redirect in Next.js versions
CVE-2021-43803
Unexpected server crash in Next.js.
CVE-2021-39178
XSS in Image Optimization API for Next.js
CVE-2021-37699
Open Redirect in Next.js
CVE-2025-29927
Authorization Bypass in Next.js Middleware
GHSA-h25m-26qc-wcjf
Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
CVE-2025-59471
Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
CVE-2024-56332
Next.js Allows a Denial of Service (DoS) with Server Actions
CVE-2025-55173
Next.js Content Injection Vulnerability for Image Optimization
CVE-2025-57822
Next.js Improper Middleware Redirect Handling Leads to SSRF
GHSA-mwv6-3258-q52c
Next Vulnerable to Denial of Service with Server Components
CVE-2024-46982
Next.js Cache Poisoning
GHSA-9qr9-h5gf-34mp
Next.js is vulnerable to RCE in React flight protocol
CVE-2024-34351
Next.js Server-Side Request Forgery in Server Actions
CVE-2024-47831
Denial of Service condition in Next.js image optimization
GHSA-w37m-7fhw-fmv9
Next Server Actions Source Code Exposure
CVE-2025-57752
Next.js Affected by Cache Key Confusion for Image Optimization API Routes
GHSA-5j59-xgg2-r9c4
Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
CVE-2025-49005
Next.js has a Cache poisoning vulnerability due to omission of the Vary header
CVE-2025-30218
Next.js may leak x-middleware-subrequest-id to external hosts
CVE-2020-5284
Directory Traversal in Next.js
CVE-2025-32421
Next.js Race Condition to Cache Poisoning
CVE-2024-51479
Next.js authorization bypass vulnerability
CVE-2025-49826
Next.JS vulnerability can lead to DoS via cache poisoning
CVE-2025-48068
Information exposure in Next.js dev server due to lack of origin verification
CVE-2024-39693
Next.js Denial of Service (DoS) condition
CVE-2024-34350
Next.js Vulnerable to HTTP Request Smuggling
CVE-2017-16877
Next.js Directory Traversal Vulnerability
CVE-2023-46298
Next.js missing cache-control header may lead to CDN caching empty reply
CVE-2022-36046
Unexpected server crash in Next.js
CVE-2022-23646
Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.1.0
CVE-2022-21721
Denial of Service Vulnerability in next.js
CVE-2018-6184
Directory traversal vulnerability in Next.js
CVE-2018-18282
Next.js has cross site scripting (XSS) vulnerability via the 404 or 500 /_error page
GHSA-5vj8-3v2h-h38v
Remote Code Execution in next
Ready to move
Start Securing
Free, no credit card | First findings in minutes