Threat Advisory

Next.js Flaws Let Attackers Bypass Middleware and Proxy

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Next.js, a popular React-based framework for building server-side rendered and statically generated websites and applications. The affected versions are not explicitly stated in the article, but multiple patches are available to address these issues.

CVE-2026-64641 (CVSS 7.5 — High): A Denial of Service vulnerability exists in App Router using Server Actions, allowing an attacker to cause a crash or hang.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Next.js, a popular React-based framework for building server-side rendered and statically generated websites and applications. The affected versions are not explicitly stated in the article, but multiple patches are available to address these issues.

CVE-2026-64641 (CVSS 7.5 — High): A Denial of Service vulnerability exists in App Router using Server Actions, allowing an attacker to cause a crash or hang.[emaillocker id="1283"]

CVE-2026-64642: Next.js Middleware / Proxy bypass in App Router applications using Turbopack and single locale allows an attacker to bypass security restrictions.

CVE-2026-64643 (CVSS 8.1 — Critical): An Unauthenticated disclosure of internal Server Function endpoints vulnerability exists, allowing an attacker to access sensitive data.

CVE-2026-64644: A Denial of Service vulnerability in the Image Optimization API using SVGs allows an attacker to cause a crash or hang.

CVE-2026-64645 (CVSS 7.5 — High): Server-Side Request Forgery in rewrites via attacker-controlled destination hostname exists, allowing an attacker to make requests on behalf of the victim.

CVE-2026-64646: Unbounded Server Action payload in Edge runtime allows an attacker to cause a crash or hang.

CVE-2026-64647 (CVSS 5.3 — Medium): Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences exists, allowing an attacker to access sensitive data.

CVE-2026-64648: Cache confusion of response bodies for requests with bodies allows an attacker to access sensitive data.

CVE-2026-64649 (CVSS 7.5 — High): Server-Side Request Forgery in Server Actions on custom servers exists, allowing an attacker to make requests on behalf of the victim. These vulnerabilities collectively present a significant risk to Next.js users, particularly those who rely heavily on server-side rendering and statically generated websites and applications. Administrators should apply available patches to mitigate these issues. These vulnerabilities collectively present a significant risk to Next.js users, particularly those who rely heavily on server-side rendering and statically generated websites and applications.

These vulnerabilities collectively present a significant risk to Next.js users, particularly those who rely heavily on server-side rendering and statically generated websites and applications.

RECOMMENDATION:

We recommend you update Next to version 15.5.21 or 16.2.11

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu