Intel

AIKIDO-2026-10760

next is vulnerable to Denial of Service

Denial of ServiceGHSA-mg66-mrh9-m8jx

75

High Risk

This Affects:

JSnext
15.0.0 - 15.5.15
Fixed in 15.5.16
16.0.0 - 16.2.4
Fixed in 16.2.5
Are you affected? Scan for Free

TL;DR

Cache Component request flows can be forced into a body-handling deadlock that keeps connections open for too long. Repeated crafted requests can exhaust file descriptors and worker capacity. This enables availability degradation through connection exhaustion. The fix strips internal resume headers from untrusted input and prevents this deadlock path from external traffic.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

next is vulnerable to Denial of Service in versions 15.0.0 - 15.5.15 and 16.0.0 - 16.2.4.

How to fix this

Upgrade the next library to the patch version.