// advisories
Is the stack on fire?
Open advisories from the GitHub Advisory Database, matched against the versions this site actually runs.
Stack is clear12 watched · just now
ai6.0.1972 advisories · all patched
drizzle-orm0.45.22 advisories · all patched
next16.3.0159 advisories · all patched
- Next.js: Server-Side Request Forgery in Server Actions on custom servers · patched in 15.5.21HIGH
- Next.js: Server-Side Request Forgery in Server Actions on custom servers · patched in 16.2.11HIGH
- Next.js: Cache confusion of response bodies for requests with bodies · patched in 15.5.21MODERATE
- Next.js: Cache confusion of response bodies for requests with bodies · patched in 16.2.11MODERATE
- Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences · patched in 15.5.21MODERATE
- Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences · patched in 16.2.11MODERATE
- Next.js: Unbounded Server Action payload in Edge runtime · patched in 15.5.21MODERATE
- Next.js: Unbounded Server Action payload in Edge runtime · patched in 16.2.11MODERATE
- Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname · patched in 15.5.21HIGH
- Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname · patched in 16.2.11HIGH
- Next.js: Denial of Service in the Image Optimization API using SVGs · patched in 15.5.21MODERATE
- Next.js: Denial of Service in the Image Optimization API using SVGs · patched in 16.2.11MODERATE
- Next.js: Unauthenticated disclosure of internal Server Function endpoints · patched in 15.5.21MODERATE
- Next.js: Unauthenticated disclosure of internal Server Function endpoints · patched in 16.2.11MODERATE
- Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale · patched in 16.2.11HIGH
- Next.js: Denial of Service in App Router using Server Actions · patched in 15.5.21HIGH
- Next.js: Denial of Service in App Router using Server Actions · patched in 16.2.11HIGH
- Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up · patched in 15.5.18HIGH
- Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up · patched in 16.2.6HIGH
- Next.js's Middleware / Proxy redirects can be cache-poisoned · patched in 15.5.16LOW
- Next.js's Middleware / Proxy redirects can be cache-poisoned · patched in 16.2.5LOW
- Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces · patched in 15.5.16MODERATE
- Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces · patched in 16.2.5MODERATE
- Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting · patched in 15.5.16LOW
- Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting · patched in 16.2.5LOW
- Next.js has cross-site scripting in beforeInteractive scripts with untrusted input · patched in 15.5.16MODERATE
- Next.js has cross-site scripting in beforeInteractive scripts with untrusted input · patched in 16.2.5MODERATE
- Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components · patched in 15.5.16HIGH
- Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components · patched in 16.2.5HIGH
- Next.js has a Denial of Service in the Image Optimization API · patched in 15.5.16MODERATE
- Next.js has a Denial of Service in the Image Optimization API · patched in 16.2.5MODERATE
- Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades · patched in 15.5.16HIGH
- Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades · patched in 16.2.5HIGH
- Next.js vulnerable to cache poisoning in React Server Component responses · patched in 15.5.16MODERATE
- Next.js vulnerable to cache poisoning in React Server Component responses · patched in 16.2.5MODERATE
- Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes · patched in 15.5.16HIGH
- Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes · patched in 16.2.5HIGH
- Next.js has a Middleware / Proxy bypass through dynamic route parameter injection · patched in 15.5.16HIGH
- Next.js has a Middleware / Proxy bypass through dynamic route parameter injection · patched in 16.2.5HIGH
- Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n · patched in 15.5.16HIGH
- Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n · patched in 16.2.5HIGH
- Next.js Vulnerable to Denial of Service with Server Components · patched in 15.5.16HIGH
- Next.js Vulnerable to Denial of Service with Server Components · patched in 16.2.5HIGH
- Next.js has a Denial of Service with Server Components · patched in 15.5.15HIGH
- Next.js has a Denial of Service with Server Components · patched in 16.2.3HIGH
- Next.js: HTTP request smuggling in rewrites · patched in 16.1.7MODERATE
- Next.js: HTTP request smuggling in rewrites · patched in 15.5.13MODERATE
- Next.js: Unbounded next/image disk cache growth can exhaust storage · patched in 16.1.7MODERATE
- Next.js: Unbounded next/image disk cache growth can exhaust storage · patched in 15.5.14MODERATE
- Next.js: Unbounded postponed resume buffering can lead to DoS · patched in 16.1.7MODERATE
- Next.js: null origin can bypass Server Actions CSRF checks · patched in 16.1.7MODERATE
- Next.js: null origin can bypass dev HMR websocket CSRF checks · patched in 16.1.7LOW
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components · patched in 15.0.8HIGH
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components · patched in 15.1.12HIGH
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components · patched in 15.2.9HIGH
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components · patched in 15.3.9HIGH
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components · patched in 15.4.11HIGH
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components · patched in 15.5.10HIGH
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components · patched in 15.6.0-canary.61HIGH
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components · patched in 16.0.11HIGH
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components · patched in 16.1.5HIGH
- Next.js has Unbounded Memory Consumption via PPR Resume Endpoint · patched in 16.1.5MODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume Endpoint · patched in 15.6.0-canary.61MODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js has Unbounded Memory Consumption via PPR Resume EndpointMODERATE
- Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration · patched in 15.5.10MODERATE
- Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration · patched in 16.1.5MODERATE
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up · patched in 14.2.35HIGH
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up · patched in 15.0.7HIGH
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up · patched in 15.1.11HIGH
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up · patched in 15.2.8HIGH
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up · patched in 15.3.8HIGH
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up · patched in 15.4.10HIGH
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up · patched in 15.5.9HIGH
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up · patched in 15.6.0-canary.60HIGH
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up · patched in 16.0.10HIGH
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up · patched in 16.1.0-canary.19HIGH
- Next Server Actions Source Code Exposure · patched in 15.0.6MODERATE
- Next Server Actions Source Code Exposure · patched in 15.1.10MODERATE
- Next Server Actions Source Code Exposure · patched in 15.2.7MODERATE
- Next Server Actions Source Code Exposure · patched in 15.3.7MODERATE
- Next Server Actions Source Code Exposure · patched in 15.4.9MODERATE
- Next Server Actions Source Code Exposure · patched in 15.5.8MODERATE
- Next Server Actions Source Code Exposure · patched in 15.6.0-canary.59MODERATE
- Next Server Actions Source Code Exposure · patched in 16.0.9MODERATE
- Next Server Actions Source Code Exposure · patched in 16.1.0-canary.17MODERATE
- Next Vulnerable to Denial of Service with Server Components · patched in 14.2.34HIGH
- Next Vulnerable to Denial of Service with Server Components · patched in 15.0.6HIGH
- Next Vulnerable to Denial of Service with Server Components · patched in 15.1.10HIGH
- Next Vulnerable to Denial of Service with Server Components · patched in 15.2.7HIGH
- Next Vulnerable to Denial of Service with Server Components · patched in 15.3.7HIGH
- Next Vulnerable to Denial of Service with Server Components · patched in 15.4.9HIGH
- Next Vulnerable to Denial of Service with Server Components · patched in 15.5.8HIGH
- Next Vulnerable to Denial of Service with Server Components · patched in 15.6.0-canary.59HIGH
- Next Vulnerable to Denial of Service with Server Components · patched in 16.0.9HIGH
- Next Vulnerable to Denial of Service with Server Components · patched in 16.1.0-canary.17HIGH
- Next.js is vulnerable to RCE in React flight protocol · patched in 15.0.5CRITICAL
- Next.js is vulnerable to RCE in React flight protocol · patched in 15.2.6CRITICAL
- Next.js is vulnerable to RCE in React flight protocol · patched in 15.3.6CRITICAL
- Next.js is vulnerable to RCE in React flight protocol · patched in 15.4.8CRITICAL
- Next.js is vulnerable to RCE in React flight protocol · patched in 16.0.7CRITICAL
- Next.js is vulnerable to RCE in React flight protocol · patched in 15.1.9CRITICAL
- Next.js is vulnerable to RCE in React flight protocol · patched in 15.5.7CRITICAL
- Next.js Affected by Cache Key Confusion for Image Optimization API Routes · patched in 15.4.5MODERATE
- Next.js Affected by Cache Key Confusion for Image Optimization API Routes · patched in 14.2.31MODERATE
- Next.js Content Injection Vulnerability for Image Optimization · patched in 15.4.5MODERATE
- Next.js Content Injection Vulnerability for Image Optimization · patched in 14.2.31MODERATE
- Next.js Improper Middleware Redirect Handling Leads to SSRF · patched in 15.4.7MODERATE
- Next.js Improper Middleware Redirect Handling Leads to SSRF · patched in 14.2.32MODERATE
- Next.JS vulnerability can lead to DoS via cache poisoning · patched in 15.1.8HIGH
- Next.js has a Cache poisoning vulnerability due to omission of the Vary header · patched in 15.3.3LOW
- Information exposure in Next.js dev server due to lack of origin verification · patched in 15.2.2LOW
- Information exposure in Next.js dev server due to lack of origin verification · patched in 14.2.30LOW
- Next.js Race Condition to Cache Poisoning · patched in 15.1.6LOW
- Next.js Race Condition to Cache Poisoning · patched in 14.2.24LOW
- Next.js may leak x-middleware-subrequest-id to external hosts · patched in 12.3.6LOW
- Next.js may leak x-middleware-subrequest-id to external hosts · patched in 13.5.10LOW
- Next.js may leak x-middleware-subrequest-id to external hosts · patched in 14.2.26LOW
- Next.js may leak x-middleware-subrequest-id to external hosts · patched in 15.2.4LOW
- Authorization Bypass in Next.js Middleware · patched in 13.5.9CRITICAL
- Authorization Bypass in Next.js Middleware · patched in 14.2.25CRITICAL
- Authorization Bypass in Next.js Middleware · patched in 15.2.3CRITICAL
- Authorization Bypass in Next.js Middleware · patched in 12.3.5CRITICAL
- Next.js Allows a Denial of Service (DoS) with Server Actions · patched in 13.5.8MODERATE
- Next.js Allows a Denial of Service (DoS) with Server Actions · patched in 14.2.21MODERATE
- Next.js Allows a Denial of Service (DoS) with Server Actions · patched in 15.1.2MODERATE
- Next.js authorization bypass vulnerability · patched in 14.2.15HIGH
- Denial of Service condition in Next.js image optimization · patched in 14.2.7MODERATE
- Next.js Cache Poisoning · patched in 13.5.7HIGH
- Next.js Cache Poisoning · patched in 14.2.10HIGH
- Next.js Denial of Service (DoS) condition · patched in 13.5.0HIGH
- Next.js Server-Side Request Forgery in Server Actions · patched in 14.1.1HIGH
- Next.js Vulnerable to HTTP Request Smuggling · patched in 13.5.1HIGH
- Next.js missing cache-control header may lead to CDN caching empty reply · patched in 13.4.20-canary.13LOW
- Unexpected server crash in Next.js · patched in 12.2.4MODERATE
- Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.1.0 · patched in 12.1.0MODERATE
- Denial of Service Vulnerability in next.js · patched in 12.0.9MODERATE
- Unexpected server crash in Next.js. · patched in 12.0.5HIGH
- Unexpected server crash in Next.js. · patched in 11.1.3HIGH
- XSS in Image Optimization API for Next.js · patched in 11.1.1HIGH
- Open Redirect in Next.js · patched in 11.1.0MODERATE
- Open Redirect in Next.js versions · patched in 9.5.4MODERATE
- Remote Code Execution in next · patched in 5.1.0HIGH
- Directory Traversal in Next.js · patched in 9.3.2MODERATE
- Next.js has cross site scripting (XSS) vulnerability via the 404 or 500 /_error page · patched in 7.0.2MODERATE
- Directory traversal vulnerability in Next.js · patched in 4.2.3HIGH
- Next.js Directory Traversal Vulnerability · patched in 2.4.1HIGH
next-mdx-remote6.0.01 advisory · all patched
react19.2.63 advisories · all patched
react-dom19.2.65 advisories · all patched
- Cross-Site Scripting in react-dom · patched in 16.0.1MODERATE
- Cross-Site Scripting in react-dom · patched in 16.1.2MODERATE
- Cross-Site Scripting in react-dom · patched in 16.2.1MODERATE
- Cross-Site Scripting in react-dom · patched in 16.3.3MODERATE
- Cross-Site Scripting in react-dom · patched in 16.4.2MODERATE