PT-2026-63561 · Vercel · Next.Js
CVE-2026-64646
·
Published
2026-07-22
·
Updated
2026-07-28
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Next.js versions 13.0.0 through 15.5.20
Next.js versions 16.0.0 through 16.2.10
Description
Requests targeting applications using App Router with at least one Server Action can lead to excessive memory consumption when that Server Action utilizes the Edge runtime, which is a lightweight environment designed to run code closer to the user.
Recommendations
Update Next.js versions 13.0.0 through 15.5.20 to version 15.5.21.
Update Next.js versions 16.0.0 through 16.2.10 to version 16.2.11.
Ensure the hosting provider limits the request body size to a maximum of 5 MiB.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Next.Js