next is vulnerable to Denial of Service
70
High Risk
Security researchers have discovered that a malicious HTTP request can be crafted and sent to any Server Functions endpoint that, when deserialized by React, can cause an infinite loop that hangs the server process and consumes CPU. Even if your app does not implement any React Server Function endpoints it may still be vulnerable if your app supports React Server Components.
If your application uses React Server Components with the App Router.
next is vulnerable to Denial of Service in versions 13.3.0 - 14.2.34, 15.0.0 - 15.0.6, 15.1.1 - 15.1.10, 15.2.0 - 15.2.7, 15.3.0 - 15.3.7, 15.4.0 - 15.4.9, 15.5.1 - 15.5.8 and 16.0.0 - 16.0.9.
Upgrade Next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant