Launch Week Day 1: Announcing Security Design Review
55 Total advisories
55 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 5.4
npm

CVE-2026-44576

Next.js vulnerable to cache poisoning in React Server Component responses

LOW 3.7
npm

CVE-2026-44582

Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

MEDIUM 5.9
npm

CVE-2026-44577

Next.js has a Denial of Service in the Image Optimization API

MEDIUM 6.1
npm

CVE-2026-44580

Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

MEDIUM 4.7
npm

CVE-2026-44581

Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces

HIGH 7.5
npm

CVE-2026-44579

Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components

HIGH 8.6
npm

CVE-2026-44578

Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades

LOW 3.7
npm

CVE-2026-44572

Next.js's Middleware / Proxy redirects can be cache-poisoned

HIGH 7.5
npm

CVE-2026-44573

Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n

HIGH 7.5
npm

CVE-2026-44575

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes

HIGH 8.1
npm

CVE-2026-44574

Next.js has a Middleware / Proxy bypass through dynamic route parameter injection

HIGH 7.5
npm

CVE-2026-45109

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up

HIGH 7.5
npm

GHSA-8h8q-6873-q5fj

Next.js Vulnerable to Denial of Service with Server Components

HIGH 7.5
npm

GHSA-q4gf-8mx6-v5v3

Next.js has a Denial of Service with Server Components

MEDIUM 5.9
npm

CVE-2025-59472

Next.js has Unbounded Memory Consumption via PPR Resume Endpoint

UNKNOWN
npm

CVE-2026-27977

Next.js: null origin can bypass dev HMR websocket CSRF checks

UNKNOWN
npm

CVE-2026-27980

Next.js: Unbounded next/image disk cache growth can exhaust storage

UNKNOWN
npm

CVE-2026-27979

Next.js: Unbounded postponed resume buffering can lead to DoS

UNKNOWN
npm

CVE-2026-27978

Next.js: null origin can bypass Server Actions CSRF checks

UNKNOWN
npm

CVE-2026-29057

Next.js: HTTP request smuggling in rewrites

MEDIUM 4.7
npm

CVE-2020-15242

Open Redirect in Next.js versions

HIGH 7.5
npm

CVE-2021-43803

Unexpected server crash in Next.js.

HIGH 7.5
npm

CVE-2021-39178

XSS in Image Optimization API for Next.js

MEDIUM 6.9
npm

CVE-2021-37699

Open Redirect in Next.js

CRITICAL 9.1
npm

CVE-2025-29927

Authorization Bypass in Next.js Middleware

HIGH 7.5
npm

GHSA-h25m-26qc-wcjf

Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

MEDIUM 5.9
npm

CVE-2025-59471

Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

MEDIUM 5.3
npm

CVE-2024-56332

Next.js Allows a Denial of Service (DoS) with Server Actions

MEDIUM 4.3
npm

CVE-2025-55173

Next.js Content Injection Vulnerability for Image Optimization

MEDIUM 6.5
npm

CVE-2025-57822

Next.js Improper Middleware Redirect Handling Leads to SSRF

HIGH 7.5
npm

GHSA-mwv6-3258-q52c

Next Vulnerable to Denial of Service with Server Components

HIGH 7.5
npm

CVE-2024-46982

Next.js Cache Poisoning

CRITICAL 10.0
npm

GHSA-9qr9-h5gf-34mp

Next.js is vulnerable to RCE in React flight protocol

HIGH 7.5
npm

CVE-2024-34351

Next.js Server-Side Request Forgery in Server Actions

MEDIUM 5.9
npm

CVE-2024-47831

Denial of Service condition in Next.js image optimization

MEDIUM 5.3
npm

GHSA-w37m-7fhw-fmv9

Next Server Actions Source Code Exposure

MEDIUM 6.2
npm

CVE-2025-57752

Next.js Affected by Cache Key Confusion for Image Optimization API Routes

HIGH 7.5
npm

GHSA-5j59-xgg2-r9c4

Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

LOW 3.7
npm

CVE-2025-49005

Next.js has a Cache poisoning vulnerability due to omission of the Vary header

UNKNOWN
npm

CVE-2025-30218

Next.js may leak x-middleware-subrequest-id to external hosts

MEDIUM 4.4
npm

CVE-2020-5284

Directory Traversal in Next.js

LOW 3.7
npm

CVE-2025-32421

Next.js Race Condition to Cache Poisoning

HIGH 7.5
npm

CVE-2024-51479

Next.js authorization bypass vulnerability

HIGH 7.5
npm

CVE-2025-49826

Next.JS vulnerability can lead to DoS via cache poisoning

UNKNOWN
npm

CVE-2025-48068

Information exposure in Next.js dev server due to lack of origin verification

HIGH 7.5
npm

CVE-2024-39693

Next.js Denial of Service (DoS) condition

HIGH 7.5
npm

CVE-2024-34350

Next.js Vulnerable to HTTP Request Smuggling

HIGH 7.5
npm

CVE-2017-16877

Next.js Directory Traversal Vulnerability

UNKNOWN
npm

CVE-2023-46298

Next.js missing cache-control header may lead to CDN caching empty reply

MEDIUM 5.3
npm

CVE-2022-36046

Unexpected server crash in Next.js

MEDIUM 5.9
npm

CVE-2022-23646

Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.1.0

MEDIUM 5.9
npm

CVE-2022-21721

Denial of Service Vulnerability in next.js

HIGH 7.5
npm

CVE-2018-6184

Directory traversal vulnerability in Next.js

MEDIUM 6.1
npm

CVE-2018-18282

Next.js has cross site scripting (XSS) vulnerability via the 404 or 500 /_error page

UNKNOWN
npm

GHSA-5vj8-3v2h-h38v

Remote Code Execution in next

Ready to move

Start Securing

Free, no credit card | First findings in minutes