PT-2026-63561 · Vercel · Next.Js

CVE-2026-64646

·

Published

2026-07-22

·

Updated

2026-07-28

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Next.js versions 13.0.0 through 15.5.20 Next.js versions 16.0.0 through 16.2.10
Description Requests targeting applications using App Router with at least one Server Action can lead to excessive memory consumption when that Server Action utilizes the Edge runtime, which is a lightweight environment designed to run code closer to the user.
Recommendations Update Next.js versions 13.0.0 through 15.5.20 to version 15.5.21. Update Next.js versions 16.0.0 through 16.2.10 to version 16.2.11. Ensure the hosting provider limits the request body size to a maximum of 5 MiB.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64646
GHSA-4C39-4CCG-62R3

Affected Products

Next.Js