next is vulnerable to Denial of Service (DoS)
63
Medium Risk
Next.js applications using the App Router with at least one Server Action running on the Edge runtime accept the request body for that action without enforcing an upper size bound. A request carrying a large body is buffered into memory, so oversized or repeated requests drive excessive memory consumption in the serving process. This lets an unauthenticated caller exhaust memory and degrade availability. The fix bounds the accepted Server Action payload size on the Edge runtime.
You are affected if you are using a version that falls within the vulnerable range and your application uses the App Router with at least one Server Action on the Edge runtime.
next is vulnerable to Denial of Service (DoS) in versions 13.0.0 - 15.5.20 and 16.0.0 - 16.2.10.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant