Junglewise Threat Intelligence

CVE-2026-27979: Next.js unbounded postponed resume buffering DoS

CVE-2026-27979 · Severity: medium · CVSS 4 · Published 2026-03-17

Technologies: Vercel Next.js. Vendors: Vercel.

Executive brief

Next.js is a React-based web framework used to build server-rendered and static web applications. In versions 16.1.0 through 16.1.6, applications using Partial Prerendering can be targeted by attackers sending specially crafted requests with oversized payloads. These requests bypass size limits and consume excessive memory on the server, leading to service degradation or outages.

Technical details

The vulnerability is an insufficient input validation issue (CWE-770) in Next.js's handling of Partial Prerendering (PPR) resume requests. Requests containing the `next-resume: 1` header trigger buffering of request bodies to restore postponed component state. In non-minimal deployments, the `maxPostponedStateSize` limit was not consistently enforced across all buffering paths, allowing attackers to send POST payloads that exceed configured limits without triggering errors. The attack requires the application to have PPR enabled via `experimental.ppr` or `cacheComponents` configuration and network access to send the malicious request. Successful exploitation causes excessive memory consumption leading to denial of service. The issue is fixed in version 16.1.7 by enforcing size limits consistently across all postponed-body buffering paths.

Affected products

  • Vercel Next.js 16.1.0 through 16.1.6

Timeline

  • 2026-03-17: disclosed: GHSA-h27x-g6w4-24gq published
  • 2026-03-17: patched: Fixed in Next.js 16.1.7
  • 2026-03-18: other: CVE-2026-27979 assigned

References

Related threats