Dependency scanning
Check whether next is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-34351
Next.js Server-Side Request Forgery in Server Actions
CVE-2025-48068
Information exposure in Next.js dev server due to lack of origin verification
CVE-2022-21721
Denial of Service Vulnerability in next.js
CVE-2020-15242
Open Redirect in Next.js versions
CVE-2020-5284
Directory Traversal in Next.js
GHSA-2xp9-vwfh-vxw4
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
CVE-2026-75604
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
GHSA-9qr9-h5gf-34mp
Next.js is vulnerable to RCE in React flight protocol
CVE-2026-64647
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
CVE-2026-64649
Next.js: Server-Side Request Forgery in Server Actions on custom servers
CVE-2026-64644
Next.js: Denial of Service in the Image Optimization API using SVGs
CVE-2026-64645
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
CVE-2026-64648
Next.js: Cache confusion of response bodies for requests with bodies
CVE-2026-64646
Next.js: Unbounded Server Action payload in Edge runtime
CVE-2026-64643
Next.js: Unauthenticated disclosure of internal Server Function endpoints
CVE-2026-64642
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
CVE-2026-64641
Next.js: Denial of Service in App Router using Server Actions
CVE-2022-36046
Unexpected server crash in Next.js
CVE-2021-43803
Unexpected server crash in Next.js.
CVE-2021-39178
XSS in Image Optimization API for Next.js
CVE-2021-37699
Open Redirect in Next.js
CVE-2026-44576
Next.js vulnerable to cache poisoning in React Server Component responses
CVE-2026-44582
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
CVE-2026-44577
Next.js has a Denial of Service in the Image Optimization API
CVE-2026-44580
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
CVE-2026-44581
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
CVE-2026-44579
Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components
CVE-2026-44578
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
CVE-2026-44572
Next.js's Middleware / Proxy redirects can be cache-poisoned
CVE-2026-44573
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
CVE-2026-44575
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVE-2026-44574
Next.js has a Middleware / Proxy bypass through dynamic route parameter injection
CVE-2026-45109
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
GHSA-8h8q-6873-q5fj
Next.js Vulnerable to Denial of Service with Server Components
GHSA-q4gf-8mx6-v5v3
Next.js has a Denial of Service with Server Components
CVE-2025-59472
Next.js has Unbounded Memory Consumption via PPR Resume Endpoint
CVE-2026-27977
Next.js: null origin can bypass dev HMR websocket CSRF checks
CVE-2026-27980
Next.js: Unbounded next/image disk cache growth can exhaust storage
CVE-2026-27979
Next.js: Unbounded postponed resume buffering can lead to DoS
CVE-2026-27978
Next.js: null origin can bypass Server Actions CSRF checks
CVE-2026-29057
Next.js: HTTP request smuggling in rewrites
CVE-2025-29927
Authorization Bypass in Next.js Middleware
GHSA-h25m-26qc-wcjf
Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
CVE-2025-59471
Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
CVE-2024-56332
Next.js Allows a Denial of Service (DoS) with Server Actions
CVE-2025-55173
Next.js Content Injection Vulnerability for Image Optimization
CVE-2025-57822
Next.js Improper Middleware Redirect Handling Leads to SSRF
GHSA-mwv6-3258-q52c
Next Vulnerable to Denial of Service with Server Components
CVE-2024-46982
Next.js Cache Poisoning
CVE-2024-47831
Denial of Service condition in Next.js image optimization
GHSA-w37m-7fhw-fmv9
Next Server Actions Source Code Exposure
CVE-2025-57752
Next.js Affected by Cache Key Confusion for Image Optimization API Routes
GHSA-5j59-xgg2-r9c4
Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
CVE-2025-49005
Next.js has a Cache poisoning vulnerability due to omission of the Vary header
CVE-2025-30218
Next.js may leak x-middleware-subrequest-id to external hosts
CVE-2025-32421
Next.js Race Condition to Cache Poisoning
CVE-2024-51479
Next.js authorization bypass vulnerability
CVE-2025-49826
Next.JS vulnerability can lead to DoS via cache poisoning
CVE-2024-39693
Next.js Denial of Service (DoS) condition
CVE-2024-34350
Next.js Vulnerable to HTTP Request Smuggling
CVE-2017-16877
Next.js Directory Traversal Vulnerability
CVE-2023-46298
Next.js missing cache-control header may lead to CDN caching empty reply
CVE-2022-23646
Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.1.0
CVE-2018-6184
Directory traversal vulnerability in Next.js
CVE-2018-18282
Next.js has cross site scripting (XSS) vulnerability via the 404 or 500 /_error page
GHSA-5vj8-3v2h-h38v
Remote Code Execution in next
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes