Executive brief
Next.js is a popular React framework used to build web applications. A vulnerability in Server Components allows attackers to craft malicious HTTP requests that cause the server process to hang and consume excessive CPU resources, disrupting service availability for all users.
Technical details
The vulnerability exists in React packages (versions 19.0.0–19.2.1) and Next.js frameworks using the App Router (versions 13.3+) when processing untrusted HTTP requests. The root cause involves unsafe deserialization of malformed HTTP payloads sent to App Router endpoints, which can trigger infinite loops or resource exhaustion in the server process. Attack vector is network-based with no authentication or user interaction required. An attacker can send a single crafted HTTP request to any App Router endpoint to cause denial of service. Patches are available across affected version lines (14.2.34, 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 16.0.9, and later canary versions).
Affected products
- Vercel Next.js 13.3.0 through 14.2.33, 15.0.0-canary.0 through 15.5.7, 15.6.0-canary.0 through 15.6.0-canary.58, 16.0.0-beta.0 through 16.0.8, 16.1.0-canary.0 through 16.1.0-canary.16
Timeline
- 2025-12-11: disclosed: Vulnerability disclosed via GitHub Security Advisory GHSA-mwv6-3258-q52c
- 2025-12-11: patched: Patches released for multiple version lines (14.2.34, 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 16.0.9)