OSS Support Hub / Web Framework

Node.js Web Framework MIT Latest: v16.3.0-canary.19

Next.js

React framework for production — full-stack web applications with server-side rendering

Project Health at a Glance

Live data from GitHub and npm, updated daily.

139.5K+12
GitHub Stars
📦
v16.3.0-canary.19
Latest Release · 5 days ago
🔄
0d
Avg. Release Cadence
🐛
3.9K
Open Issues
📅
Today
Last Commit
⬇️
34.9M
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Next.js may leak x-middleware-subrequest-id to external hosts

Published: 2025-04-02 Fixed in: 12.3.6

Unexpected server crash in Next.js.

Published: 2021-12-07 Fixed in: 12.0.5

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes

Published: 2026-05-11 Fixed in: 15.5.16

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up

Published: 2026-05-11 Fixed in: 15.5.18

Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n

Published: 2026-05-11 Fixed in: 15.5.16

Next.js Directory Traversal Vulnerability

Published: 2017-12-05 Fixed in: 2.4.1

Next.js's Middleware / Proxy redirects can be cache-poisoned

Published: 2026-05-11 Fixed in: 15.5.16

Information exposure in Next.js dev server due to lack of origin verification

Published: 2025-05-28 Fixed in: 15.2.2

Next.js: Unbounded next/image disk cache growth can exhaust storage

Published: 2026-03-17 Fixed in: 16.1.7

Next.js Improper Middleware Redirect Handling Leads to SSRF

Published: 2025-08-29 Fixed in: 14.2.32

Alternatives to Next.js

Other Web Framework projects in the Node.js ecosystem worth evaluating.

Support Options for Next.js

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Next.js — without relying on volunteer maintainers.

Talk to an Expert →