Executive brief
Next.js Partial Prerendering (PPR) is a feature that optimizes web page load times. When PPR is enabled in minimal mode, the resume endpoint can be exploited to crash the application server through memory exhaustion. An attacker can send large request payloads or specially crafted compressed data that expands in memory, causing the Node.js process to terminate and resulting in application downtime.
Technical details
This denial-of-service vulnerability exists in the PPR resume endpoint when the application is configured with experimental.ppr: true or cacheComponents: true and the NEXT_PRIVATE_MINIMAL_MODE=1 environment variable. The endpoint accepts unauthenticated POST requests with the Next-Resume: 1 header and processes attacker-controlled postponed state data without proper validation. Two attack vectors enable memory exhaustion: (1) unbounded request body buffering via Buffer.concat() without size limits allows arbitrarily large payloads to exhaust available memory, and (2) unbounded decompression using inflateSync() on cached resume data allows a small compressed payload (zipbomb) to expand to hundreds of megabytes or gigabytes. Both vectors trigger a fatal V8 out-of-memory error (FATAL ERROR: Reached heap limit) that terminates the Node.js process. The zipbomb variant is particularly dangerous as it can bypass reverse proxy request size limits. Patches are available in versions 15.6.0-canary.61, 16.1.5, and later stable releases.
Affected products
- Vercel Next.js 15.0.0-canary.0 through 15.5.9, 16.0.0-beta.0 through 16.1.4
Timeline
- 2026-01-26: disclosed: Vulnerability disclosed via GitHub advisory and NVD
- 2026-01-26: patched: Fixes available in Next.js 15.6.0-canary.61 and 16.1.5