Technology · Vercel
Vercel Next.js vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 75 vulnerabilities in Vercel Next.js: 0 in the last 7 days and 13 in the last 90 days, 3 of them critical and 1 exploited in the wild. The most recent, Next.js heap buffer overflow in image optimization via malicious AVIF, was published on 8 September 2026.
- Last 7 days
- 0
- Last 90 days
- 13
- Critical, all time
- 3
- Exploited in the wild
- 1
About Vercel Next.js
A React-based web application framework for production with server-side rendering, static generation, and API routes.
Latest Vercel Next.js vulnerabilities
- Next.js heap buffer overflow in image optimization via malicious AVIFcriticalCVSS 9.5
- Next.js Image Optimization heap buffer overflow via AVIFmediumCVSS 4
- CVE-2026-75604: Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js…criticalCVSS 9EPSS 2.3%
- Next.js and libheif RCE in HEIF/AVIF image processinginfoCVSS 9.8
- CVE-2026-64649: Vercel Next.js SSRF in Server Actions on custom servershighCVSS 4EPSS 0.5%
- CVE-2026-64648: Vercel Next.js cache confusion in server-side fetchmediumCVSS 4EPSS 0.3%
- CVE-2026-64647: Vercel Next.js cache confusion in server-side fetch requestsmediumCVSS 4EPSS 0.3%
- CVE-2026-64646: Vercel Next.js denial of service in Server Actions Edge runtimemediumCVSS 4EPSS 0.5%
- CVE-2026-64645: Vercel Next.js SSRF and Open Redirect in rewrites and redirectshighCVSS 4EPSS 0.4%
- CVE-2026-64644: Vercel Next.js denial of service in Image Optimization APImediumCVSS 4EPSS 0.7%
- CVE-2026-64643: Vercel Next.js authentication bypass in Server Function endpointsmediumCVSS 4EPSS 0.5%
- CVE-2026-64642: Vercel Next.js authentication bypass in Turbopack middleware matcherhighCVSS 4EPSS 0.6%
- CVE-2026-64641: Vercel Next.js denial of service in App Router Server ActionshighCVSS 4EPSS 0.9%
- CVE-2026-45109: Vercel Next.js authentication bypass in middleware with TurbopackhighCVSS 7.5EPSS 0.8%
- CVE-2026-44582: Vercel Next.js cache poisoning in React Server ComponentslowCVSS 3.7EPSS 0.2%
- CVE-2026-44581: Vercel Next.js stored XSS in App Router via CSP nonce reflectionmediumCVSS 4.7EPSS 0.3%
- CVE-2026-44580: Vercel Next.js cross-site scripting in beforeInteractive scriptsmediumCVSS 6.1EPSS 0.3%
- CVE-2026-44579: Vercel Next.js connection exhaustion in Cache ComponentshighCVSS 7.5EPSS 0.8%
- CVE-2026-44578: Vercel Next.js SSRF via WebSocket upgrade requestshighCVSS 8.6EPSS 1.9%
- CVE-2026-44577: Vercel Next.js denial of service in Image Optimization APImediumCVSS 5.9EPSS 0.9%
- CVE-2026-44576: Vercel Next.js cache poisoning in React Server ComponentsmediumCVSS 5.4EPSS 0.3%
- CVE-2026-44575: Vercel Next.js auth bypass in App Router middlewarehighCVSS 7.5EPSS 0.8%
- CVE-2026-44574: Vercel Next.js authorization bypass in dynamic route middlewarehighCVSS 8.1EPSS 0.7%
- CVE-2026-44573: Vercel Next.js auth bypass in Pages Router via i18n data routeshighCVSS 7.5EPSS 0.8%
- CVE-2026-44572: Vercel Next.js cache poisoning in middleware redirectslowCVSS 3.7EPSS 0.2%
Most severe Vercel Next.js vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-55182: A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0…criticalexploited in the wildCVSS 10EPSS 99.8%
- Next.js heap buffer overflow in image optimization via malicious AVIFcriticalCVSS 9.5
- CVE-2026-75604: Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js…criticalCVSS 9EPSS 2.3%
- CVE-2026-44578: Vercel Next.js SSRF via WebSocket upgrade requestshighCVSS 8.6EPSS 1.9%
- CVE-2026-44574: Vercel Next.js authorization bypass in dynamic route middlewarehighCVSS 8.1EPSS 0.7%
- CVE-2026-23870: Facebook React Denial of Service in React Server ComponentshighCVSS 7.5EPSS 1.5%
- CVE-2026-45109: Vercel Next.js authentication bypass in middleware with TurbopackhighCVSS 7.5EPSS 0.8%
- CVE-2026-44579: Vercel Next.js connection exhaustion in Cache ComponentshighCVSS 7.5EPSS 0.8%
- CVE-2026-44575: Vercel Next.js auth bypass in App Router middlewarehighCVSS 7.5EPSS 0.8%
- CVE-2026-44573: Vercel Next.js auth bypass in Pages Router via i18n data routeshighCVSS 7.5EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 9 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 1 | 1 | |
| 7 Sep 2026 | 2 | 1 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/next-js.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Vercel Next.js vulnerabilities", https://junglewise.ai/threats/technologies/next-js, 26 September 2026.