HIGH
GHSA-m99w-x7hq-7vfj
Next.js: Denial of Service in App Router using Server Actions
Quick fix
GHSA-m99w-x7hq-7vfj — next: upgrade to the fixed version with the command below.
npm install next@15.5.21 Details
## Impact
Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.
## Workarounds
No workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj [WEB]
- https://github.com/vercel/next.js/pull/96013 [WEB]
- https://github.com/vercel/next.js/commit/019628571641dec57aaf349ba0c360e3964e6f12 [WEB]
- https://github.com/vercel/next.js [PACKAGE]
- https://github.com/vercel/next.js/releases/tag/v15.5.21 [WEB]
- https://github.com/vercel/next.js/releases/tag/v16.2.11 [WEB]