CVE security advisories and vulnerability history for next.js by vercel.
51
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
6
Public exploits
With known exploit
6.1
Avg CVSS
2017–2026
Last updated
Overview
vercel next.js has 51 published CVE records since 2017, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 6 have a known public exploit. The average CVSS base score across scored CVEs is 6.1.
This page aggregates every publicly disclosed vulnerability (CVE) affecting vercel next.js, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of vercel next.js's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical2
High16
Medium22
Low7
4 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of vercel next.js's CVEs is confirmed exploited in the wild.
Public exploits
6
6 of vercel next.js's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every vercel next.js version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about vercel next.js vulnerabilities.
How many CVEs does vercel next.js have?
vercel next.js has 51 published CVE records since 2017.
How many vercel next.js CVEs are in CISA KEV?
Yes — 1 of vercel next.js's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for vercel next.js vulnerabilities?
Yes — 6 of vercel next.js's CVEs have a known public exploit.
Which versions of vercel next.js are affected?
3,940 distinct vercel next.js versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in vercel next.js CVEs?
vercel next.js's CVEs most often map to these CWE weakness types: CWE-400 (Uncontrolled Resource Consumption), CWE-444 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')), CWE-770 (Allocation of Resources Without Limits or Throttling), CWE-918 (Server-Side Request Forgery (SSRF)).
How many critical vercel next.js vulnerabilities are there?
vercel next.js has 2 critical and 16 high-severity CVEs.
What is the average severity of vercel next.js CVEs?
The average CVSS base score across vercel next.js's scored CVEs is 6.1.