Skip to content
Threat Feed

Tag

Nextjs

5 briefs RSS
critical advisory

Critical RCE Vulnerability in Next.js ImageResponse via Crafted SVG Input

A critical vulnerability (CVE-2026-94545) in the Next.js ImageResponse feature allows unauthenticated remote code execution when attacker-controlled input is improperly sanitized during SVG generation.

Next.js +1 web-vulnerability rce server-side nextjs
1t
critical advisory

Unauthenticated Remote Code Execution in Next.js Image Optimization API

A critical vulnerability in the libheif dependency used by Next.js allows unauthenticated attackers to achieve remote code execution via malicious AVIF image uploads.

Next.js +1 rce vulnerability web-application nextjs
1t
critical advisory

Unauthenticated Remote Command Execution in Next.js on Windows

A critical path traversal vulnerability (CVE-2026-75604) in the Next.js FileSystemCache on Windows allows unauthenticated attackers to steal Server Action encryption keys and execute arbitrary commands.

Next.js +3 web-vulnerability rce path-traversal windows nextjs
1r 2t 1c updated
high advisory

Next.js i18n Pages Router Middleware Authentication Bypass (CVE-2026-44573)

Next.js applications using the Pages Router with `i18n` and middleware-based authorization are vulnerable to an authentication bypass (CVE-2026-44573), allowing unauthorized access to protected page data via locale-less `/_next/data/<buildId>/<page>.json` requests.

next +1 nextjs authentication-bypass vulnerability
2r 1t
high advisory

Next.js Middleware Authorization Bypass via Dynamic Route Parameter Injection (CVE-2026-44574)

A vulnerability in Next.js (CVE-2026-44574) allows for authorization bypass in applications that use middleware to protect dynamic routes, enabling attackers to render protected content without proper authorization by crafting specific query parameters.

next +1 nextjs middleware authorization bypass CVE-2026-44574 cloud
2r 1t