The React Framework
95%
Total Score
80
100
100
95
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-29057 next is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 16.0.0-beta.0 - 16.1.7 and 9.5.0 - 15.5.13. | 9.5.0 - 15.5.1316.0.0-beta.0 - 16.1.7 | Medium |
CVE-2026-27980 next is vulnerable to Uncontrolled Resource Consumption in versions 16.0.0-beta.0 - 16.1.7 and 10.0.0 - 15.5.14. | 10.0.0 - 15.5.1416.0.0-beta.0 - 16.1.7 | Medium |
CVE-2026-27979 next is vulnerable to Allocation of Resources Without Limits or Throttling in versions 16.0.1 - 16.1.7. | 16.0.1 - 16.1.7 | Medium |
CVE-2026-27978 next is vulnerable to Cross-Site Request Forgery (CSRF) in versions 16.0.1 - 16.1.7. | 16.0.1 - 16.1.7 | Medium |
CVE-2026-27977 next is vulnerable to Missing Origin Validation in WebSockets in versions 16.0.1 - 16.1.7. | 16.0.1 - 16.1.7 | Low |
| Dependency | Last Release | Score |
|---|---|---|
postcss Version 8.4.31 | — | — |
@next/env Version 16.2.4 | — | — |
styled-jsx Version 5.1.6 | — | — |
@swc/helpers Version 0.5.15 | — | — |
caniuse-lite Version ^1.0.30001579 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant