Repository navigation
Security: vercel/next.js
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Cache leak across root param values in nested 'use cache' functionsGHSA-h694-7cp9-m8p3 published
Sep 30, 2026 by eps1lonModerate -
Remote Code Execution in next/og ImageResponseGHSA-vcvr-r3jv-pc5j published
Sep 22, 2026 by KarimPwnzCritical -
Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pagesGHSA-3w37-wq28-93x7 published
Sep 30, 2026 by eps1lonModerate -
Server-Side Request Forgery in Image OptimizationGHSA-cjq9-62q9-8jv4 published
Sep 30, 2026 by eps1lonHigh -
Information disclosure in the Next.js development server's Model Context Protocol endpointGHSA-39w2-rjm5-chcv published
Sep 30, 2026 by eps1lonLow -
Cache poisoning of SSG and ISR pages in self-hosted Next.js applicationsGHSA-4jqv-mc3x-m676 published
Sep 30, 2026 by eps1lonModerate -
Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitution and persistent denial of serviceGHSA-mcj8-r9mp-w47p published
Sep 30, 2026 by eps1lonModerate -
Information disclosure in Next.js App Router metadata image routes via dynamicParams bypassGHSA-f87g-xv8r-7p7x published
Sep 30, 2026 by eps1lonModerate -
Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are usedGHSA-2xp9-vwfh-vxw4 published
Aug 25, 2026 by eps1lonCritical -
Unauthenticated Remote Code Execution on windows-hosted serversGHSA-p293-qw3h-jr36 published
Aug 25, 2026 by eps1lonCritical