CVE Explorer
CVE-2026-64643
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used. Server Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references). Affected users are ap
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"next.js","vendor":"vercel","versions":[{"status":"affected","version":">= 13.0.0, < 15.5.21"},{"status":"affected","version":">= 16.0.0, < 16.2.11"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:bdc7262edc9607809c0083eb03362e7e2c73686b6e3685920509e666409c9d6b · sha256:c357a7a90cd4c682… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:bdc7262edc9607809c0083eb03362e7e2c73686b6e3685920509e666409c9d6b · sha256:c357a7a90cd4c682… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-201","description":"CWE-201: Insertion of Sensitive Information Into Sent Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bdc7262edc9607809c0083eb03362e7e2c73686b6e3685920509e666409c9d6b · sha256:c357a7a90cd4c682… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/vercel/next.js/commit/1b0c3ae912a3ad925c60065cc8d55b070fa8bcd3","tags":["x_refsource_MISC"],"url":"https://github.com/vercel/next.js/commit/1b0c3ae912a3ad925c60065cc8d55b070fa8bcd3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bdc7262edc9607809c0083eb03362e7e2c73686b6e3685920509e666409c9d6b · sha256:c357a7a90cd4c682… · /containers/cna/references/1
{"name":"https://github.com/vercel/next.js/commit/ff12a6124e1504f17b62de948b8a553fdecaef7b","tags":["x_refsource_MISC"],"url":"https://github.com/vercel/next.js/commit/ff12a6124e1504f17b62de948b8a553fdecaef7b"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bdc7262edc9607809c0083eb03362e7e2c73686b6e3685920509e666409c9d6b · sha256:c357a7a90cd4c682… · /containers/cna/references/2
{"name":"https://github.com/vercel/next.js/releases/tag/v15.5.21","tags":["x_refsource_MISC"],"url":"https://github.com/vercel/next.js/releases/tag/v15.5.21"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bdc7262edc9607809c0083eb03362e7e2c73686b6e3685920509e666409c9d6b · sha256:c357a7a90cd4c682… · /containers/cna/references/3
{"name":"https://github.com/vercel/next.js/releases/tag/v16.2.11","tags":["x_refsource_MISC"],"url":"https://github.com/vercel/next.js/releases/tag/v16.2.11"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bdc7262edc9607809c0083eb03362e7e2c73686b6e3685920509e666409c9d6b · sha256:c357a7a90cd4c682… · /containers/cna/references/4
{"name":"https://github.com/vercel/next.js/security/advisories/GHSA-955p-x3mx-jcvp","tags":["x_refsource_CONFIRM"],"url":"https://github.com/vercel/next.js/security/advisories/GHSA-955p-x3mx-jcvp"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bdc7262edc9607809c0083eb03362e7e2c73686b6e3685920509e666409c9d6b · sha256:c357a7a90cd4c682… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.