Multiple security vulnerabilities have been identified in Next.js, a popular React-based framework for building server-side rendered and statically generated websites and applications. The affected versions are not explicitly stated in the article, but multiple patches are available to address these issues.
CVE-2026-64641 (CVSS 7.5 — High): A Denial of Service vulnerability exists in App Router using Server Actions, allowing an attacker to cause a crash or hang.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in Next.js, a popular React-based framework for building server-side rendered and statically generated websites and applications. The affected versions are not explicitly stated in the article, but multiple patches are available to address these issues.
CVE-2026-64641 (CVSS 7.5 — High): A Denial of Service vulnerability exists in App Router using Server Actions, allowing an attacker to cause a crash or hang.[emaillocker id="1283"]
CVE-2026-64642: Next.js Middleware / Proxy bypass in App Router applications using Turbopack and single locale allows an attacker to bypass security restrictions.
CVE-2026-64643 (CVSS 8.1 — Critical): An Unauthenticated disclosure of internal Server Function endpoints vulnerability exists, allowing an attacker to access sensitive data.
CVE-2026-64644: A Denial of Service vulnerability in the Image Optimization API using SVGs allows an attacker to cause a crash or hang.
CVE-2026-64645 (CVSS 7.5 — High): Server-Side Request Forgery in rewrites via attacker-controlled destination hostname exists, allowing an attacker to make requests on behalf of the victim.
CVE-2026-64646: Unbounded Server Action payload in Edge runtime allows an attacker to cause a crash or hang.
CVE-2026-64647 (CVSS 5.3 — Medium): Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences exists, allowing an attacker to access sensitive data.
CVE-2026-64648: Cache confusion of response bodies for requests with bodies allows an attacker to access sensitive data.
CVE-2026-64649 (CVSS 7.5 — High): Server-Side Request Forgery in Server Actions on custom servers exists, allowing an attacker to make requests on behalf of the victim. These vulnerabilities collectively present a significant risk to Next.js users, particularly those who rely heavily on server-side rendering and statically generated websites and applications. Administrators should apply available patches to mitigate these issues. These vulnerabilities collectively present a significant risk to Next.js users, particularly those who rely heavily on server-side rendering and statically generated websites and applications.
These vulnerabilities collectively present a significant risk to Next.js users, particularly those who rely heavily on server-side rendering and statically generated websites and applications.
We recommend you update Next to version 15.5.21 or 16.2.11
The following reports contain further technical details:
[/emaillocker]