Junglewise Threat Intelligence

CVE-2026-44579: Vercel Next.js connection exhaustion in Cache Components

CVE-2026-44579 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: Vercel Next.js. Vendors: Vercel.

Executive brief

Next.js is a popular web development framework used to build high-performance websites and applications. A vulnerability in its 'Partial Prerendering' feature allows attackers to crash or slow down a website by sending specially crafted web requests. This can lead to a denial of service, where legitimate customers are unable to access the site, potentially impacting business operations and reputation.

Technical details

A denial of service vulnerability exists in Next.js versions 15.x and 16.x when Partial Prerendering (PPR) and Cache Components are enabled. The flaw is rooted in how the server handles the 'Next-Resume' header, which is intended for internal use during request resumption. An unauthenticated remote attacker can send a crafted POST request to a server action that triggers a request-body handling deadlock. This deadlock exhausts server resources by leaving connections open and consuming file descriptors until the service becomes unresponsive. The issue is resolved in versions 15.5.16 and 16.2.5 by treating the resumption header as internal-only and stripping it from incoming client requests.

Affected products

  • Vercel Next.js >= 15.0.0, < 15.5.16; >= 16.0.0, < 16.2.5

Timeline

  • 2026-05-06: advisory: GitHub advisory published by Vercel
  • 2026-05-13: disclosed: CVE-2026-44579 published
  • 2026-05-13: patched: Fixes released in versions 15.5.16 and 16.2.5

References

Related threats