Skip to content
Vulnerabilities

Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks

Vercel has disclosed and patched nine security vulnerabilities in Next.js, the widely used React framework, addressing flaws that could enable server-side request forgery (SSRF), middleware authentication bypass, denial-of-service (DoS) attacks, and sensitive data exposure. All nine advisories were...

· Jul 23, 2026 · 3 min read · 👁 2 views
Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks

Vercel has disclosed and patched nine security vulnerabilities in Next.js, the widely used React framework, addressing flaws that could enable server-side request forgery (SSRF), middleware authentication bypass, denial-of-service (DoS) attacks, and sensitive data exposure.

All nine advisories were published two days ago by security researcher KarimPwnz and are now fixed in Next.js versions 15.5.21 and 16.2.11.

Earlier, Next.js announced it would launch a monthly security release program. This update will address nine vulnerabilities across supported versions of the framework.

Next.js Patches Multiple Vulnerabilities

The most critical issue, tracked as CVE-2026-64645 (GHSA-p9j2-gv94-2wf4), is a high-severity SSRF vulnerability affecting the rewrites feature, where an attacker-controlled destination hostname can force the server to send requests to arbitrary internal endpoints.

This flaw impacts Next.js versions 12.0.0 through 15.5.21 and 16.0.0 through 16.2.11, and is exploitable when a rewrites() or redirects() rule builds its destination hostname from user-supplied request data.

A second high-severity SSRF bug, CVE-2026-64649 (GHSA-89xv-2m56-2m9x), affects Server Actions running on custom Node.js servers, allowing attackers to redirect outbound Server Action requests to a host they control.

Separately, CVE-2026-64642 (GHSA-6gpp-xcg3-4w24) enables a middleware and proxy bypass in App Router applications that use Turbopack builds with legacy middleware.ts and single-locale i18n configurations, potentially letting attackers skip authorization checks entirely.

Rounding out the high-severity list, CVE-2026-64641 (GHSA-m99w-x7hq-7vfj) allows attackers to trigger DoS conditions in App Router applications through malicious Server Actions requests.

Two moderate-severity DoS issues were also patched: CVE-2026-64646 (GHSA-4c39-4ccg-62r3) involves unbounded Server Action payloads in the Edge runtime that can exhaust memory, while CVE-2026-64644 (GHSA-q8wf-6r8g-63ch) lets attackers crash the Image Optimization API by submitting malicious SVG files.

Two moderate-severity cache confusion bugs, CVE-2026-64648 (GHSA-68g3-v927-f742) and CVE-2026-64647 (GHSA-4633-3j49-mh5q), can cause response bodies to be mixed up between different requests when applications use cached fetch() calls with request bodies, including those containing invalid UTF-8 byte sequences.

This could lead one user’s data being served to another user under certain caching configurations. A final moderate issue, CVE-2026-64643 (GHSA-955p-x3mx-jcvp), exposes internal Server Function endpoint identifiers to unauthenticated attackers when Cache Components are used alongside reflective Server Actions, though Vercel notes the leak is limited to opaque identifiers rather than credentials or personal data.

Affected Versions and Mitigations

The vulnerabilities span a broad swath of the Next.js ecosystem, with affected version ranges starting as early as 12.0.0 for the rewrites SSRF flaw and 13.0.0 for several DoS and cache issues.

Older major versions such as 13.x and 14.x will not receive direct patches; organizations running these must upgrade to a fixed 15.x or 16.x release.

VulnerabilityCVESeverity
SSRF in rewritesCVE-2026-64645High
SSRF in Server Actions (custom servers)CVE-2026-64649High
Middleware/proxy bypassCVE-2026-64642High
DoS via Server ActionsCVE-2026-64641High
Unbounded Edge payloadCVE-2026-64646Moderate
Image Optimization DoS (SVG)CVE-2026-64644Moderate
Cache confusion (bodies)CVE-2026-64648Moderate
Cache confusion (invalid UTF-8)CVE-2026-64647Moderate
Server Function endpoint disclosureCVE-2026-64643Moderate

Security teams should upgrade Next.js to 15.5.21 or 16.2.11 immediately and audit configurations for rewrites, custom servers, Turbopack middleware, and Cache Components to determine specific exposure.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you