PT-2026-63556 · Vercel · Next.Js

CVE-2026-64641

·

Published

2026-07-22

·

Updated

2026-08-17

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Next.js versions 13.0.0 through 15.5.20 Next.js versions 16.0.0 through 16.2.10
Description Crafted requests targeting applications using App Router with at least one Server Action can cause excessive CPU usage, which blocks the processing of subsequent requests within the same process.
Recommendations Update Next.js versions 13.0.0 through 15.5.20 to version 15.5.21. Update Next.js versions 16.0.0 through 16.2.10 to version 16.2.11.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64641
GHSA-M99W-X7HQ-7VFJ

Affected Products

Next.Js