{"schema_version":1,"title":"Vercel Next.js vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 75 vulnerabilities in Vercel Next.js: 0 in the last 7 days and 13 in the last 90 days, 3 of them critical and 1 exploited in the wild. The most recent, Next.js heap buffer overflow in image optimization via malicious AVIF, was published on 8 September 2026.","url":"https://junglewise.ai/threats/technologies/next-js","json_url":"https://junglewise.ai/threats/technologies/next-js.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/next-js","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":14,"all_time":75,"critical":3,"exploited":1,"last_7_days":0,"last_30_days":3,"last_90_days":13,"last_365_days":46},"latest":[{"cvss":9.5,"slug":"next-js-heap-buffer-overflow-in-image-optimization-via-malicious-avif-90b951e0","title":"Next.js heap buffer overflow in image optimization via malicious AVIF","severity":"critical","exploited":false,"published_at":"2026-09-08T21:21:12+00:00","url":"https://junglewise.ai/threats/next-js-heap-buffer-overflow-in-image-optimization-via-malicious-avif-90b951e0"},{"cvss":4,"slug":"next-js-image-optimization-heap-buffer-overflow-via-avif-9ce530ed","title":"Next.js Image Optimization heap buffer overflow via AVIF","severity":"medium","exploited":false,"published_at":"2026-09-08T21:21:12+00:00","url":"https://junglewise.ai/threats/next-js-image-optimization-heap-buffer-overflow-via-avif-9ce530ed"},{"cve":"CVE-2026-75604","cvss":9,"epss":0.023,"slug":"cve-2026-75604-next-js-unauthenticated-remote-code-execution-on-windows","title":"Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Page","severity":"critical","exploited":false,"published_at":"2026-09-01T22:17:12.697+00:00","url":"https://junglewise.ai/threats/cve-2026-75604-next-js-unauthenticated-remote-code-execution-on-windows"},{"cvss":9.8,"slug":"next-js-and-libheif-rce-in-heif-avif-image-processing-eebb5345","title":"Next.js and libheif RCE in HEIF/AVIF image processing","severity":"info","exploited":false,"published_at":"2026-08-25T00:00:00+00:00","url":"https://junglewise.ai/threats/next-js-and-libheif-rce-in-heif-avif-image-processing-eebb5345"},{"cve":"CVE-2026-64649","cvss":4,"epss":0.0046,"slug":"cve-2026-64649-vercel-next-js-ssrf-in-server-actions-on-custom-servers","title":"Vercel Next.js SSRF in Server Actions on custom servers","severity":"high","exploited":false,"published_at":"2026-07-27T20:16:40.703+00:00","url":"https://junglewise.ai/threats/cve-2026-64649-vercel-next-js-ssrf-in-server-actions-on-custom-servers"},{"cve":"CVE-2026-64648","cvss":4,"epss":0.0034,"slug":"cve-2026-64648-vercel-next-js-cache-confusion-in-server-side-fetch","title":"Vercel Next.js cache confusion in server-side fetch","severity":"medium","exploited":false,"published_at":"2026-07-27T20:16:40.563+00:00","url":"https://junglewise.ai/threats/cve-2026-64648-vercel-next-js-cache-confusion-in-server-side-fetch"},{"cve":"CVE-2026-64647","cvss":4,"epss":0.0032,"slug":"cve-2026-64647-vercel-next-js-cache-confusion-in-server-side-fetch-requests","title":"Vercel Next.js cache confusion in server-side fetch requests","severity":"medium","exploited":false,"published_at":"2026-07-27T19:17:21.627+00:00","url":"https://junglewise.ai/threats/cve-2026-64647-vercel-next-js-cache-confusion-in-server-side-fetch-requests"},{"cve":"CVE-2026-64646","cvss":4,"epss":0.0052,"slug":"cve-2026-64646-vercel-next-js-denial-of-service-in-server-actions-edge-runtime","title":"Vercel Next.js denial of service in Server Actions Edge runtime","severity":"medium","exploited":false,"published_at":"2026-07-27T19:17:21.477+00:00","url":"https://junglewise.ai/threats/cve-2026-64646-vercel-next-js-denial-of-service-in-server-actions-edge-runtime"},{"cve":"CVE-2026-64645","cvss":4,"epss":0.0041,"slug":"cve-2026-64645-vercel-next-js-ssrf-and-open-redirect-in-rewrites-and-redirects","title":"Vercel Next.js SSRF and Open Redirect in rewrites and redirects","severity":"high","exploited":false,"published_at":"2026-07-27T18:16:59.453+00:00","url":"https://junglewise.ai/threats/cve-2026-64645-vercel-next-js-ssrf-and-open-redirect-in-rewrites-and-redirects"},{"cve":"CVE-2026-64644","cvss":4,"epss":0.0067,"slug":"cve-2026-64644-vercel-next-js-denial-of-service-in-image-optimization-api","title":"Vercel Next.js denial of service in Image Optimization API","severity":"medium","exploited":false,"published_at":"2026-07-27T18:16:59.307+00:00","url":"https://junglewise.ai/threats/cve-2026-64644-vercel-next-js-denial-of-service-in-image-optimization-api"},{"cve":"CVE-2026-64643","cvss":4,"epss":0.0051,"slug":"cve-2026-64643-vercel-next-js-authentication-bypass-in-server-function-endpoints","title":"Vercel Next.js authentication bypass in Server Function endpoints","severity":"medium","exploited":false,"published_at":"2026-07-27T18:16:59.16+00:00","url":"https://junglewise.ai/threats/cve-2026-64643-vercel-next-js-authentication-bypass-in-server-function-endpoints"},{"cve":"CVE-2026-64642","cvss":4,"epss":0.0064,"slug":"cve-2026-64642-vercel-next-js-authentication-bypass-in-turbopack-middleware","title":"Vercel Next.js authentication bypass in Turbopack middleware matcher","severity":"high","exploited":false,"published_at":"2026-07-27T18:16:59.01+00:00","url":"https://junglewise.ai/threats/cve-2026-64642-vercel-next-js-authentication-bypass-in-turbopack-middleware"},{"cve":"CVE-2026-64641","cvss":4,"epss":0.0086,"slug":"cve-2026-64641-vercel-next-js-denial-of-service-in-app-router-server-actions","title":"Vercel Next.js denial of service in App Router Server Actions","severity":"high","exploited":false,"published_at":"2026-07-27T18:16:58.85+00:00","url":"https://junglewise.ai/threats/cve-2026-64641-vercel-next-js-denial-of-service-in-app-router-server-actions"},{"cve":"CVE-2026-45109","cvss":7.5,"epss":0.0076,"slug":"cve-2026-45109-vercel-next-js-authentication-bypass-in-middleware-with-turbopack","title":"Vercel Next.js authentication bypass in middleware with Turbopack","severity":"high","exploited":false,"published_at":"2026-05-13T18:16:19.283+00:00","url":"https://junglewise.ai/threats/cve-2026-45109-vercel-next-js-authentication-bypass-in-middleware-with-turbopack"},{"cve":"CVE-2026-44582","cvss":3.7,"epss":0.0017,"slug":"cve-2026-44582-vercel-next-js-cache-poisoning-in-react-server-components","title":"Vercel Next.js cache poisoning in React Server Components","severity":"low","exploited":false,"published_at":"2026-05-13T18:16:19.037+00:00","url":"https://junglewise.ai/threats/cve-2026-44582-vercel-next-js-cache-poisoning-in-react-server-components"},{"cve":"CVE-2026-44581","cvss":4.7,"epss":0.0025,"slug":"cve-2026-44581-vercel-next-js-xss-in-app-router-via-csp-nonces","title":"Vercel Next.js stored XSS in App Router via CSP nonce reflection","severity":"medium","exploited":false,"published_at":"2026-05-13T18:16:18.4+00:00","url":"https://junglewise.ai/threats/cve-2026-44581-vercel-next-js-xss-in-app-router-via-csp-nonces"},{"cve":"CVE-2026-44580","cvss":6.1,"epss":0.0025,"slug":"cve-2026-44580-vercel-next-js-xss-in-beforeinteractive-scripts","title":"Vercel Next.js cross-site scripting in beforeInteractive scripts","severity":"medium","exploited":false,"published_at":"2026-05-13T18:16:18.26+00:00","url":"https://junglewise.ai/threats/cve-2026-44580-vercel-next-js-xss-in-beforeinteractive-scripts"},{"cve":"CVE-2026-44579","cvss":7.5,"epss":0.0076,"slug":"cve-2026-44579-vercel-next-js-connection-exhaustion-in-cache-components","title":"Vercel Next.js connection exhaustion in Cache Components","severity":"high","exploited":false,"published_at":"2026-05-13T18:16:18.123+00:00","url":"https://junglewise.ai/threats/cve-2026-44579-vercel-next-js-connection-exhaustion-in-cache-components"},{"cve":"CVE-2026-44578","cvss":8.6,"epss":0.019,"slug":"cve-2026-44578-vercel-next-js-ssrf-via-websocket-upgrade-requests","title":"Vercel Next.js SSRF via WebSocket upgrade requests","severity":"high","exploited":false,"published_at":"2026-05-13T18:16:17.99+00:00","url":"https://junglewise.ai/threats/cve-2026-44578-vercel-next-js-ssrf-via-websocket-upgrade-requests"},{"cve":"CVE-2026-44577","cvss":5.9,"epss":0.0094,"slug":"cve-2026-44577-vercel-next-js-denial-of-service-in-image-optimization-api","title":"Vercel Next.js denial of service in Image Optimization API","severity":"medium","exploited":false,"published_at":"2026-05-13T17:16:23.173+00:00","url":"https://junglewise.ai/threats/cve-2026-44577-vercel-next-js-denial-of-service-in-image-optimization-api"},{"cve":"CVE-2026-44576","cvss":5.4,"epss":0.003,"slug":"cve-2026-44576-vercel-next-js-cache-poisoning-in-react-server-components","title":"Vercel Next.js cache poisoning in React Server Components","severity":"medium","exploited":false,"published_at":"2026-05-13T17:16:23.04+00:00","url":"https://junglewise.ai/threats/cve-2026-44576-vercel-next-js-cache-poisoning-in-react-server-components"},{"cve":"CVE-2026-44575","cvss":7.5,"epss":0.0076,"slug":"cve-2026-44575-vercel-next-js-auth-bypass-in-app-router-middleware","title":"Vercel Next.js auth bypass in App Router middleware","severity":"high","exploited":false,"published_at":"2026-05-13T17:16:22.907+00:00","url":"https://junglewise.ai/threats/cve-2026-44575-vercel-next-js-auth-bypass-in-app-router-middleware"},{"cve":"CVE-2026-44574","cvss":8.1,"epss":0.0067,"slug":"cve-2026-44574-vercel-next-js-authorization-bypass-in-dynamic-route-middleware","title":"Vercel Next.js authorization bypass in dynamic route middleware","severity":"high","exploited":false,"published_at":"2026-05-13T17:16:22.767+00:00","url":"https://junglewise.ai/threats/cve-2026-44574-vercel-next-js-authorization-bypass-in-dynamic-route-middleware"},{"cve":"CVE-2026-44573","cvss":7.5,"epss":0.0076,"slug":"cve-2026-44573-vercel-next-js-auth-bypass-in-pages-router-via-i18n-data-routes","title":"Vercel Next.js auth bypass in Pages Router via i18n data routes","severity":"high","exploited":false,"published_at":"2026-05-13T17:16:22.627+00:00","url":"https://junglewise.ai/threats/cve-2026-44573-vercel-next-js-auth-bypass-in-pages-router-via-i18n-data-routes"},{"cve":"CVE-2026-44572","cvss":3.7,"epss":0.002,"slug":"cve-2026-44572-vercel-next-js-cache-poisoning-in-middleware-redirects","title":"Vercel Next.js cache poisoning in middleware redirects","severity":"low","exploited":false,"published_at":"2026-05-13T16:16:58.8+00:00","url":"https://junglewise.ai/threats/cve-2026-44572-vercel-next-js-cache-poisoning-in-middleware-redirects"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Vercel AI SDK","slug":"ai-sdk","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/ai-sdk"},{"name":"Vercel Turbo","slug":"turbo","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/turbo"}],"technology":{"hub":true,"name":"Vercel Next.js","slug":"next-js","vendor":{"name":"Vercel","slug":"vercel","url":"https://junglewise.ai/threats/vendors/vercel"},"aliases":[],"category":"framework","homepage":"https://nextjs.org","description":"A React-based web application framework for production with server-side rendering, static generation, and API routes.","url":"https://junglewise.ai/threats/technologies/next-js"},"most_severe":[{"cve":"CVE-2025-55182","cvss":10,"epss":0.998,"slug":"cve-2025-55182-meta-react-server-components-remote-code-execution","title":"A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu","severity":"critical","exploited":true,"published_at":"2025-12-03T16:15:56.463+00:00","url":"https://junglewise.ai/threats/cve-2025-55182-meta-react-server-components-remote-code-execution"},{"cvss":9.5,"slug":"next-js-heap-buffer-overflow-in-image-optimization-via-malicious-avif-90b951e0","title":"Next.js heap buffer overflow in image optimization via malicious AVIF","severity":"critical","exploited":false,"published_at":"2026-09-08T21:21:12+00:00","url":"https://junglewise.ai/threats/next-js-heap-buffer-overflow-in-image-optimization-via-malicious-avif-90b951e0"},{"cve":"CVE-2026-75604","cvss":9,"epss":0.023,"slug":"cve-2026-75604-next-js-unauthenticated-remote-code-execution-on-windows","title":"Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Page","severity":"critical","exploited":false,"published_at":"2026-09-01T22:17:12.697+00:00","url":"https://junglewise.ai/threats/cve-2026-75604-next-js-unauthenticated-remote-code-execution-on-windows"},{"cve":"CVE-2026-44578","cvss":8.6,"epss":0.019,"slug":"cve-2026-44578-vercel-next-js-ssrf-via-websocket-upgrade-requests","title":"Vercel Next.js SSRF via WebSocket upgrade requests","severity":"high","exploited":false,"published_at":"2026-05-13T18:16:17.99+00:00","url":"https://junglewise.ai/threats/cve-2026-44578-vercel-next-js-ssrf-via-websocket-upgrade-requests"},{"cve":"CVE-2026-44574","cvss":8.1,"epss":0.0067,"slug":"cve-2026-44574-vercel-next-js-authorization-bypass-in-dynamic-route-middleware","title":"Vercel Next.js authorization bypass in dynamic route middleware","severity":"high","exploited":false,"published_at":"2026-05-13T17:16:22.767+00:00","url":"https://junglewise.ai/threats/cve-2026-44574-vercel-next-js-authorization-bypass-in-dynamic-route-middleware"},{"cve":"CVE-2026-23870","cvss":7.5,"epss":0.0153,"slug":"cve-2026-23870-facebook-react-denial-of-service-in-react-server-components","title":"Facebook React Denial of Service in React Server Components","severity":"high","exploited":false,"published_at":"2026-05-11T14:50:07+00:00","url":"https://junglewise.ai/threats/cve-2026-23870-facebook-react-denial-of-service-in-react-server-components"},{"cve":"CVE-2026-45109","cvss":7.5,"epss":0.0076,"slug":"cve-2026-45109-vercel-next-js-authentication-bypass-in-middleware-with-turbopack","title":"Vercel Next.js authentication bypass in middleware with Turbopack","severity":"high","exploited":false,"published_at":"2026-05-13T18:16:19.283+00:00","url":"https://junglewise.ai/threats/cve-2026-45109-vercel-next-js-authentication-bypass-in-middleware-with-turbopack"},{"cve":"CVE-2026-44579","cvss":7.5,"epss":0.0076,"slug":"cve-2026-44579-vercel-next-js-connection-exhaustion-in-cache-components","title":"Vercel Next.js connection exhaustion in Cache Components","severity":"high","exploited":false,"published_at":"2026-05-13T18:16:18.123+00:00","url":"https://junglewise.ai/threats/cve-2026-44579-vercel-next-js-connection-exhaustion-in-cache-components"},{"cve":"CVE-2026-44575","cvss":7.5,"epss":0.0076,"slug":"cve-2026-44575-vercel-next-js-auth-bypass-in-app-router-middleware","title":"Vercel Next.js auth bypass in App Router middleware","severity":"high","exploited":false,"published_at":"2026-05-13T17:16:22.907+00:00","url":"https://junglewise.ai/threats/cve-2026-44575-vercel-next-js-auth-bypass-in-app-router-middleware"},{"cve":"CVE-2026-44573","cvss":7.5,"epss":0.0076,"slug":"cve-2026-44573-vercel-next-js-auth-bypass-in-pages-router-via-i18n-data-routes","title":"Vercel Next.js auth bypass in Pages Router via i18n data routes","severity":"high","exploited":false,"published_at":"2026-05-13T17:16:22.627+00:00","url":"https://junglewise.ai/threats/cve-2026-44573-vercel-next-js-auth-bypass-in-pages-router-via-i18n-data-routes"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}