Next.js 是一个用于构建全栈 Web 应用的 React 框架。在版本 13.0.0 至 15.5.20,以及 16.0.0 至 16.2.10 中,针对使用了 App Router 且至少包含一个 Server Action 的 Next.js 应用发送精心构造的请求,可能导致 CPU 使用率过高,从而阻塞同一进程内后续请求的处理。该问题已在版本 15.5.21 和 16.2.11 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64642 | 8.3 HIGH | Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single l |
| CVE-2026-64645 | 8.3 HIGH | Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostn |
| CVE-2026-64649 | 8.3 HIGH | Next.js: Server-Side Request Forgery in Server Actions on Custom Servers |
| CVE-2026-64643 | 6.3 MEDIUM | Next.js: Unauthenticated Disclosure of Internal Server Function endpoints |
| CVE-2026-64644 | 6.3 MEDIUM | Next.js: Denial of Service in the Image Optimization API using SVGs |
| CVE-2026-64646 | 6.3 MEDIUM | Next.js: Unbounded Server Action payload in Edge runtime |
| CVE-2026-64647 | 6.3 MEDIUM | Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies |
| CVE-2026-64648 | 6.0 MEDIUM | Next.js: Response Body Cache Confusion for Requests Containing Bodies |
No comments yet