Catalog / Next.js

Next.js security advisories

All 61 advisories Next.js has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
6160 carry a CVE
critical
4
high
22
medium
29
low
6
Fix in the archive
30of 61 matched to a release
Oldest
30 Mar 20206.4 years ago

31 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2026-64647medium

Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

GHSA-4633-3j49-mh5qFixed in 16.2.11
CVE-2026-64642high

Middleware / Proxy bypass in App Router applications using Turbopack and single locale

GHSA-6gpp-xcg3-4w24Fixed in 16.2.11
CVE-2026-45109high

Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up

GHSA-26hh-7cqf-hhc6Fixed in 16.2.6
CVE-2026-27977medium

Origin: null can bypass allowedDevOrigins protections for internal dev endpoints

GHSA-jcc7-9wpm-mj36Fixed in 16.1.7
CVE-2026-23864high

Denial of Service with Server Components

GHSA-h25m-26qc-wcjfFixed in 15.0.8, not held here
CVE-2025-59472medium

Denial of Service in Partial Pre Rendering

GHSA-5f7q-jpqc-wp7hFixed in 15.0.0, not held here
CVE-2025-59471medium

Denial of Service in Image Optimizer

GHSA-9g9p-9gw9-jx7fFixed in 15.5.10, not held here
CVE-2025-55184high

Denial of Service with Server Components

GHSA-mwv6-3258-q52cFixed in 16.0.9, not held here
CVE-2025-55183medium

Server Actions Source Code Exposure

GHSA-w37m-7fhw-fmv9Fixed in 16.0.9, not held here
CVE-2025-67779high

Denial of Service with Server Components - Incomplete Fix Follow-Up

GHSA-5j59-xgg2-r9c4Fixed in 14.2.35, not held here
CVE-2025-55182critical

RCE in React Server Components

GHSA-9qr9-h5gf-34mpFixed in 16.0.7, not held here
CVE-2025-57752medium

Cache Key Confusion for Image Optimization API Routes

GHSA-g5qg-72qw-gw5vFixed in 15.4.5, not held here
CVE-2025-55173medium

Content Injection for Image Optimization

GHSA-xv57-4mr9-wg8vFixed in 15.4.5, not held here
CVE-2025-57822medium

Improper Middleware Redirect Handling Leads to SSRF

GHSA-4342-x723-ch2fFixed in 14.2.32, not held here
CVE-2025-49826high

DoS via cache poisoning

GHSA-67rr-84xm-4c7rFixed in 15.0.4, not held here
CVE-2025-49005low

Cache poisoning due to omission of Vary header

GHSA-r2fc-ccr8-96c4Fixed in 15.3.3, not held here
CVE-2025-48068low

Information exposure in Next.js dev server due to lack of origin verification

GHSA-3h52-269p-cp9rFixed in 14.2.30, not held here
CVE-2025-32421low

Race condition to Cache Poisoning

GHSA-qpjv-v59x-3qc4Fixed in 14.2.24, not held here
CVE-2025-30218low

x-middleware-subrequest-id may be leaked to external hosts

GHSA-223j-4rm8-mrmfFixed in 12.3.6, not held here
CVE-2025-29927critical

Authorization Bypass in Next.js Middleware

GHSA-f82v-jwr5-mffwFixed in 12.3.5, not held here
CVE-2024-56332medium

Denial of Service (DoS) with Server Actions

GHSA-7m27-7ghc-44w9Fixed in 15.1.2, not held here
CVE-2024-51479high

Authorization bypass in Next.js

GHSA-7gfc-8cq8-jh5fFixed in 14.2.15, not held here
CVE-2024-47831medium

Denial of Service condition in Next.js image optimization

GHSA-g77x-44xx-532mFixed in 14.2.7, not held here
CVE-2024-46982high

Cache Poisoning

GHSA-gp8f-8m3g-qvj9Fixed in 13.5.7, not held here
CVE-2024-39693high

Denial of Service (DoS) condition

GHSA-fq54-2j52-jc42Fixed in 13.5, not held here
CVE-2024-34351high

Server-Side Request Forgery in Server Actions

GHSA-fr5h-rqp8-mj6gFixed in 14.1.1, not held here
CVE-2024-34350high

HTTP Request Smuggling

GHSA-77r5-gw3j-2mpfFixed in 13.5.1, not held here
CVE-2022-36046medium

Unexpected server crash in Next.js version 12.2.3

GHSA-wff4-fpwg-qqv3Fixed in 12.2.4, not held here
CVE-2022-23646medium

Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.0.10

GHSA-fmvm-x8mv-47mjFixed in 12.1.0, not held here
CVE-2022-21721medium

DOS Vulnerability for self-hosted next.js apps using i18n

GHSA-wr66-vrwm-5g5xFixed in 12.0.9, not held here
CVE-2021-43803high

Unexpected server crash in Next.js versions above 11.1.0 and below 12.0.5

GHSA-25mp-g6fv-mqxxFixed in 12.0.5, not held here
CVE-2021-39178medium

XSS in Image Optimization API for Next.js versions between 10.0.0 and 11.1.0

GHSA-9gr3-7897-pp7mFixed in 11.1.1, not held here
CVE-2021-37699medium

Open Redirect in Next.js versions below 11.1.0

GHSA-vxf5-wxwp-m7g9Fixed in 11.1.0, not held here
CVE-2020-15242medium

Open Redirect in Next.js versions between 9.5.0 and 9.5.3

GHSA-x56p-c8cg-q435Fixed in 9.5.4, not held here
CVE-2020-5284medium

Directory Traversal in Next.js versions below 9.3.2

GHSA-fq77-7p7r-83rjFixed in 9.3.2, not held here