Intel

AIKIDO-2026-10762

next is vulnerable to Denial of Service

Denial of ServiceCVE-2026-23870

75

High Risk

This Affects:

JSnext
13.0.0 - 15.5.15
Fixed in 15.5.16
16.0.0 - 16.2.4
Fixed in 16.2.5
Are you affected? Scan for Free

TL;DR

Server Components request handling can consume excessive CPU when deserializing crafted input to server function endpoints. An attacker can repeatedly trigger heavy processing and exhaust request handling capacity. This degrades application availability without requiring prior access. The fix hardens deserialization behavior to prevent unbounded compute usage from malformed payloads.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

next is vulnerable to Denial of Service in versions 13.0.0 - 15.5.15 and 16.0.0 - 16.2.4.

How to fix this

Upgrade the next library to the patch version.