« Volver al listado

Vercel

Vercel Next.js: vulnerabilidades y CVE

Vercel Next.js tiene 70 vulnerabilidades publicadas, 42 de ellas en los últimos 12 meses. 4 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE70
Últimos 12 meses42
Críticas4
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-55182Crítica (10)100%⚠ Explotación activa3 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel,…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-94544Media (6.3)——2 oct 2026
Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An…
CVE-2026-94543Media (6.3)——2 oct 2026
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration…
CVE-2026-94486Baja (2.3)——2 oct 2026
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint without reliably restricting cross-site…
CVE-2026-94485Media (6.3)——2 oct 2026
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricting cross-site…
CVE-2026-94484Media (6.3)——2 oct 2026
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Static Regeneration…
CVE-2026-94483Alta (8.3)——2 oct 2026
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns,…
CVE-2026-103004Media (6.3)0.32%—1 oct 2026
Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a…
CVE-2026-75604Crítica (9)2.3%—1 sept 2026
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do…
CVE-2026-64649Alta (8.3)0.46%—27 jul 2026
Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the…
CVE-2026-64648Media (6)0.34%—27 jul 2026
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a…
CVE-2026-64647Media (6.3)0.32%—27 jul 2026
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a…
CVE-2026-64646Media (6.3)0.52%—27 jul 2026
Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server…
CVE-2026-64645Alta (8.3)0.41%—27 jul 2026
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from…
CVE-2026-64644Media (6.3)0.67%—27 jul 2026
Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API…
CVE-2026-64643Media (6.3)0.51%—27 jul 2026
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache…
CVE-2026-64642Alta (8.3)0.64%—27 jul 2026
Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in…
CVE-2026-64641Alta (8.2)0.86%—27 jul 2026
Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one…
CVE-2025-71389Crítica (10)1.4%—23 jul 2026
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled…
CVE-2026-45109Alta (7.5)0.76%—13 may 2026
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This…
CVE-2026-44582Baja (3.7)0.17%—13 may 2026
Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared…
CVE-2026-44581Media (4.7)0.25%—13 may 2026
Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when…
CVE-2026-44580Media (6.1)0.25%—13 may 2026
Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to…
CVE-2026-44579Alta (7.5)0.76%—13 may 2026
Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection…
CVE-2026-44578Alta (8.6)1.9%—13 may 2026
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request…
CVE-2026-44577Media (5.9)0.94%—13 may 2026
Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images…
CVE-2026-44576Media (5.4)0.30%—13 may 2026
Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not…
CVE-2026-44575Alta (7.5)0.76%—13 may 2026
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow…
CVE-2026-44574Alta (8.1)0.67%—13 may 2026
Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass.…
CVE-2026-44573Alta (7.5)0.76%—13 may 2026
Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can…
CVE-2026-44572Media (5.9)0.20%—13 may 2026
Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application28
  2. T1499.004 Application or System Exploitation8
  3. T1005 Data from Local System6
  4. T1078 Valid Accounts5
  5. T1090 Proxy4
  6. T1059 Command and Scripting Interpreter2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Vercel