Vercel
Vercel Next.js: vulnerabilidades y CVE
Vercel Next.js tiene 70 vulnerabilidades publicadas, 42 de ellas en los últimos 12 meses. 4 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE70
Últimos 12 meses42
Críticas4
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-55182 | Crítica (10) | 100% | ⚠ Explotación activa | 3 dic 2025 | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel,… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-94544 | Media (6.3) | — | — | 2 oct 2026 | Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An… |
| CVE-2026-94543 | Media (6.3) | — | — | 2 oct 2026 | Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration… |
| CVE-2026-94486 | Baja (2.3) | — | — | 2 oct 2026 | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint without reliably restricting cross-site… |
| CVE-2026-94485 | Media (6.3) | — | — | 2 oct 2026 | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricting cross-site… |
| CVE-2026-94484 | Media (6.3) | — | — | 2 oct 2026 | Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Static Regeneration… |
| CVE-2026-94483 | Alta (8.3) | — | — | 2 oct 2026 | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns,… |
| CVE-2026-103004 | Media (6.3) | 0.32% | — | 1 oct 2026 | Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a… |
| CVE-2026-75604 | Crítica (9) | 2.3% | — | 1 sept 2026 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do… |
| CVE-2026-64649 | Alta (8.3) | 0.46% | — | 27 jul 2026 | Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the… |
| CVE-2026-64648 | Media (6) | 0.34% | — | 27 jul 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a… |
| CVE-2026-64647 | Media (6.3) | 0.32% | — | 27 jul 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a… |
| CVE-2026-64646 | Media (6.3) | 0.52% | — | 27 jul 2026 | Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server… |
| CVE-2026-64645 | Alta (8.3) | 0.41% | — | 27 jul 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from… |
| CVE-2026-64644 | Media (6.3) | 0.67% | — | 27 jul 2026 | Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API… |
| CVE-2026-64643 | Media (6.3) | 0.51% | — | 27 jul 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache… |
| CVE-2026-64642 | Alta (8.3) | 0.64% | — | 27 jul 2026 | Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in… |
| CVE-2026-64641 | Alta (8.2) | 0.86% | — | 27 jul 2026 | Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one… |
| CVE-2025-71389 | Crítica (10) | 1.4% | — | 23 jul 2026 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled… |
| CVE-2026-45109 | Alta (7.5) | 0.76% | — | 13 may 2026 | Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This… |
| CVE-2026-44582 | Baja (3.7) | 0.17% | — | 13 may 2026 | Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared… |
| CVE-2026-44581 | Media (4.7) | 0.25% | — | 13 may 2026 | Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when… |
| CVE-2026-44580 | Media (6.1) | 0.25% | — | 13 may 2026 | Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to… |
| CVE-2026-44579 | Alta (7.5) | 0.76% | — | 13 may 2026 | Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection… |
| CVE-2026-44578 | Alta (8.6) | 1.9% | — | 13 may 2026 | Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request… |
| CVE-2026-44577 | Media (5.9) | 0.94% | — | 13 may 2026 | Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images… |
| CVE-2026-44576 | Media (5.4) | 0.30% | — | 13 may 2026 | Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not… |
| CVE-2026-44575 | Alta (7.5) | 0.76% | — | 13 may 2026 | Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow… |
| CVE-2026-44574 | Alta (8.1) | 0.67% | — | 13 may 2026 | Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass.… |
| CVE-2026-44573 | Alta (7.5) | 0.76% | — | 13 may 2026 | Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can… |
| CVE-2026-44572 | Media (5.9) | 0.20% | — | 13 may 2026 | Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.