Junglewise Threat Intelligence

Next.js denial of service in Server Components

Severity: low · CVSS 3.1 · Published 2025-12-11

Technologies: Vercel Next.js. Vendors: Vercel.

Executive brief

Next.js is a popular React framework used to build web applications. A vulnerability in Server Components allows attackers to craft malicious HTTP requests that cause the server process to hang and consume excessive CPU resources, disrupting service availability for all users.

Technical details

The vulnerability exists in React packages (versions 19.0.0–19.2.1) and Next.js frameworks using the App Router (versions 13.3+) when processing untrusted HTTP requests. The root cause involves unsafe deserialization of malformed HTTP payloads sent to App Router endpoints, which can trigger infinite loops or resource exhaustion in the server process. Attack vector is network-based with no authentication or user interaction required. An attacker can send a single crafted HTTP request to any App Router endpoint to cause denial of service. Patches are available across affected version lines (14.2.34, 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 16.0.9, and later canary versions).

Affected products

  • Vercel Next.js 13.3.0 through 14.2.33, 15.0.0-canary.0 through 15.5.7, 15.6.0-canary.0 through 15.6.0-canary.58, 16.0.0-beta.0 through 16.0.8, 16.1.0-canary.0 through 16.1.0-canary.16

Timeline

  • 2025-12-11: disclosed: Vulnerability disclosed via GitHub Security Advisory GHSA-mwv6-3258-q52c
  • 2025-12-11: patched: Patches released for multiple version lines (14.2.34, 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 16.0.9)

References

Related threats