Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
Next.js may leak x-middleware-subrequest-id to external hosts
Unexpected server crash in Next.js.
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
Next.js Directory Traversal Vulnerability
Next.js's Middleware / Proxy redirects can be cache-poisoned
Information exposure in Next.js dev server due to lack of origin verification
Next.js: Unbounded next/image disk cache growth can exhaust storage
Next.js Improper Middleware Redirect Handling Leads to SSRF
Get SLA-backed support, security patches, and direct access to senior engineers for Next.js — without relying on volunteer maintainers.
Talk to an Expert →