next vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-27979Mediumnext: Next.js: Unbounded postponed resume buffering can lead to DoSCVE-2026-27978Mediumnext: Next.js: null origin can bypass Server Actions CSRF checksCVE-2026-27977Lownext: Next.js: null origin can bypass dev HMR websocket CSRF checksGHSA-H25M-26QC-WCJFHighnext: Next.js HTTP request deserialization can lead to DoS when using insecure React Server ComponentsCVE-2025-59472Mediumnext: Next.js has Unbounded Memory Consumption via PPR Resume Endpoint CVE-2025-59471Mediumnext: Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configurationGHSA-5J59-XGG2-R9C4Highnext: Next has a Denial of Service with Server Components - Incomplete Fix Follow-UpGHSA-W37M-7FHW-FMV9Mediumnext: Next Server Actions Source Code Exposure GHSA-MWV6-3258-Q52CHighnext: Next Vulnerable to Denial of Service with Server ComponentsGHSA-9QR9-H5GF-34MPCriticalnext: Next.js is vulnerable to RCE in React flight protocolCVE-2025-57752Mediumnext: Next.js Affected by Cache Key Confusion for Image Optimization API RoutesCVE-2025-55173Mediumnext: Next.js Content Injection Vulnerability for Image OptimizationCVE-2025-57822Mediumnext: Next.js Improper Middleware Redirect Handling Leads to SSRFCVE-2025-49826Highnext: Next.JS vulnerability can lead to DoS via cache poisoning CVE-2025-49005Lownext: Next.js has a Cache poisoning vulnerability due to omission of the Vary headerCVE-2025-48068Lownext: Information exposure in Next.js dev server due to lack of origin verificationCVE-2025-32421Lownext: Next.js Race Condition to Cache PoisoningCVE-2025-30218Lownext: Next.js may leak x-middleware-subrequest-id to external hostsCVE-2025-29927Criticalnext: Authorization Bypass in Next.js MiddlewareCVE-2024-56332Mediumnext: Next.js Allows a Denial of Service (DoS) with Server ActionsCVE-2024-51479Highnext: Next.js authorization bypass vulnerabilityCVE-2024-47831Mediumnext: Denial of Service condition in Next.js image optimizationCVE-2024-46982Highnext: Next.js Cache PoisoningCVE-2024-39693Highnext: Next.js Denial of Service (DoS) conditionCVE-2024-34351Highnext: Next.js Server-Side Request Forgery in Server Actions

Stop the waste.
Protect your environment with Kodem.