Repository navigation
Security: vercel/next.js
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Server-Side Request Forgery in rewrites via attacker-controlled destination hostnameGHSA-p9j2-gv94-2wf4 published
Jul 21, 2026 by KarimPwnzHigh -
Unbounded Server Action payload in Edge runtimeGHSA-4c39-4ccg-62r3 published
Jul 21, 2026 by KarimPwnzModerate -
Server-Side Request Forgery in Server Actions on custom serversGHSA-89xv-2m56-2m9x published
Jul 21, 2026 by KarimPwnzHigh -
Cache confusion of response bodies for requests with bodiesGHSA-68g3-v927-f742 published
Jul 21, 2026 by KarimPwnzModerate -
Middleware / Proxy bypass in App Router applications using Turbopack and single localeGHSA-6gpp-xcg3-4w24 published
Jul 21, 2026 by KarimPwnzHigh -
Denial of Service in App Router using Server ActionsGHSA-m99w-x7hq-7vfj published
Jul 21, 2026 by KarimPwnzHigh -
Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequencesGHSA-4633-3j49-mh5q published
Jul 21, 2026 by KarimPwnzModerate -
Denial of Service in the Image Optimization API using SVGsGHSA-q8wf-6r8g-63ch published
Jul 21, 2026 by KarimPwnzModerate -
Unauthenticated disclosure of internal Server Function endpointsGHSA-955p-x3mx-jcvp published
Jul 21, 2026 by KarimPwnzModerate -
Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-UpGHSA-26hh-7cqf-hhc6 published
May 7, 2026 by timneutkensHigh