Next.js
64 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Next.js, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Next.js CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 1 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 1 |
| 2025-05 | 2 |
| 2025-06 | 0 |
| 2025-07 | 2 |
| 2025-08 | 3 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 4 |
| 2026-01 | 3 |
| 2026-02 | 0 |
| 2026-03 | 5 |
| 2026-04 | 1 |
| 2026-05 | 13 |
| 2026-06 | 0 |
| 2026-07 | 9 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 64 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High24
- Medium32
- Low4
Latest CVEs
The 15 most recently published vulnerabilities affecting Next.js.
- CVE-2026-75604Next.js: Unauthenticated Remote Code Execution on windows-hosted servers9.0
- CVE-2026-64649Next.js: Server-Side Request Forgery in Server Actions on Custom Servers6.5
- CVE-2026-64648Next.js: Response Body Cache Confusion for Requests Containing Bodies5.4
- CVE-2026-64647Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies5.4
- CVE-2026-64646Next.js: Unbounded Server Action payload in Edge runtime5.3
- CVE-2026-64644Next.js: Denial of Service in the Image Optimization API using SVGs5.3
- CVE-2026-64643Next.js: Unauthenticated Disclosure of Internal Server Function endpoints5.3
- CVE-2026-64642Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale8.2
- CVE-2026-64641Next.js: Denial of Service in App Router using Server Actions7.5
- CVE-2026-64645Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname6.1
- CVE-2026-45109Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes7.5
- CVE-2026-44582Next.js: Cache poisoning via collisions in React Server Component cache-busting3.7
- CVE-2026-44581Next.js: Cross-site scripting in App Router applications using CSP nonces4.7
- CVE-2026-44580Next.js: Cross-site scripting in beforeInteractive scripts with untrusted input6.1
- CVE-2026-44579Next.js: Denial of Service via connection exhaustion in applications using Cache Components7.5
Product grouping is registry-driven, with AI assist and human review. How it works