Unauthenticated Remote Code Execution on windows-hosted servers
Next.js security advisories
All 61 advisories Next.js has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 6160 carry a CVE
- critical
- 4
- high
- 22
- medium
- 29
- low
- 6
- Fix in the archive
- 30of 61 matched to a release
- Oldest
- 30 Mar 20206.4 years ago
31 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Unauthenticated disclosure of internal Server Function endpoints
Denial of Service in the Image Optimization API using SVGs
Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Denial of Service in App Router using Server Actions
Middleware / Proxy bypass in App Router applications using Turbopack and single locale
Cache confusion of response bodies for requests with bodies
Server-Side Request Forgery in Server Actions on custom servers
Unbounded Server Action payload in Edge runtime
Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
Middleware / Proxy redirects can be cache-poisoned
Denial of Service with Server Components
Middleware / Proxy bypass in Pages Router applications using i18n
Cache poisoning in React Server Component responses
Server-side request forgery in applications using WebSocket upgrades
Denial of Service in the Image Optimization API
Middleware / Proxy bypass through dynamic route parameter injection
Denial of Service via connection exhaustion in applications using Cache Components
Cross-site scripting in beforeInteractive scripts with untrusted input
Cache poisoning via collisions in React Server Component cache-busting
Cross-site scripting in App Router applications using CSP nonces
Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Denial of Service with Server Components
HTTP request smuggling in rewrites
Unbounded postponed resume buffering can lead to DoS
Origin: null can bypass allowedDevOrigins protections for internal dev endpoints
null origin can bypass Server Actions CSRF checks
Unbounded next/image disk cache growth can exhaust storage
Denial of Service with Server Components
Denial of Service in Partial Pre Rendering
Denial of Service in Image Optimizer
Denial of Service with Server Components
Server Actions Source Code Exposure
Denial of Service with Server Components - Incomplete Fix Follow-Up
RCE in React Server Components
Cache Key Confusion for Image Optimization API Routes
Content Injection for Image Optimization
Improper Middleware Redirect Handling Leads to SSRF
DoS via cache poisoning
Cache poisoning due to omission of Vary header
Information exposure in Next.js dev server due to lack of origin verification
Race condition to Cache Poisoning
x-middleware-subrequest-id may be leaked to external hosts
Authorization Bypass in Next.js Middleware
Denial of Service (DoS) with Server Actions
Authorization bypass in Next.js
Denial of Service condition in Next.js image optimization
Cache Poisoning
Denial of Service (DoS) condition
Server-Side Request Forgery in Server Actions
HTTP Request Smuggling
Unexpected server crash in Next.js version 12.2.3
Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.0.10
DOS Vulnerability for self-hosted next.js apps using i18n
Unexpected server crash in Next.js versions above 11.1.0 and below 12.0.5
XSS in Image Optimization API for Next.js versions between 10.0.0 and 11.1.0
Open Redirect in Next.js versions below 11.1.0
Open Redirect in Next.js versions between 9.5.0 and 9.5.3
Directory Traversal in Next.js versions below 9.3.2