Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64642 | 8.3 HIGH | Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single l |
| CVE-2026-64645 | 8.3 HIGH | Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostn |
| CVE-2026-64649 | 8.3 HIGH | Next.js: Server-Side Request Forgery in Server Actions on Custom Servers |
| CVE-2026-64641 | 8.2 HIGH | Next.js: Denial of Service in App Router using Server Actions |
| CVE-2026-64644 | 6.3 MEDIUM | Next.js: Denial of Service in the Image Optimization API using SVGs |
| CVE-2026-64646 | 6.3 MEDIUM | Next.js: Unbounded Server Action payload in Edge runtime |
| CVE-2026-64647 | 6.3 MEDIUM | Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies |
| CVE-2026-64648 | 6.0 MEDIUM | Next.js: Response Body Cache Confusion for Requests Containing Bodies |
No comments yet