CVE Explorer
CVE-2026-64641
Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. This issue has been fixed in versions 15.5.21 and 16.2.11.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"next.js","vendor":"vercel","versions":[{"status":"affected","version":">= 13.0.0, < 15.5.21"},{"status":"affected","version":">= 16.0.0, < 16.2.11"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6ebed7f9d5580044b9234b3716c2d97312380f0117a427f0a8055ab544138246 · sha256:3444bbd05b4c8401… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":8.2,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6ebed7f9d5580044b9234b3716c2d97312380f0117a427f0a8055ab544138246 · sha256:3444bbd05b4c8401… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-834","description":"CWE-834: Excessive Iteration","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6ebed7f9d5580044b9234b3716c2d97312380f0117a427f0a8055ab544138246 · sha256:3444bbd05b4c8401… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/vercel/next.js/commit/019628571641dec57aaf349ba0c360e3964e6f12","tags":["x_refsource_MISC"],"url":"https://github.com/vercel/next.js/commit/019628571641dec57aaf349ba0c360e3964e6f12"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6ebed7f9d5580044b9234b3716c2d97312380f0117a427f0a8055ab544138246 · sha256:3444bbd05b4c8401… · /containers/cna/references/2
{"name":"https://github.com/vercel/next.js/pull/96013","tags":["x_refsource_MISC"],"url":"https://github.com/vercel/next.js/pull/96013"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6ebed7f9d5580044b9234b3716c2d97312380f0117a427f0a8055ab544138246 · sha256:3444bbd05b4c8401… · /containers/cna/references/1
{"name":"https://github.com/vercel/next.js/releases/tag/v15.5.21","tags":["x_refsource_MISC"],"url":"https://github.com/vercel/next.js/releases/tag/v15.5.21"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6ebed7f9d5580044b9234b3716c2d97312380f0117a427f0a8055ab544138246 · sha256:3444bbd05b4c8401… · /containers/cna/references/3
{"name":"https://github.com/vercel/next.js/releases/tag/v16.2.11","tags":["x_refsource_MISC"],"url":"https://github.com/vercel/next.js/releases/tag/v16.2.11"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6ebed7f9d5580044b9234b3716c2d97312380f0117a427f0a8055ab544138246 · sha256:3444bbd05b4c8401… · /containers/cna/references/4
{"name":"https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6ebed7f9d5580044b9234b3716c2d97312380f0117a427f0a8055ab544138246 · sha256:3444bbd05b4c8401… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.