VYPR
Medium severity4.3NVD Advisory· Published Mar 18, 2026· Updated Jun 17, 2026

CVE-2026-27978

CVE-2026-27978

Description

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, origin: null was treated as a "missing" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing actions with victim credentials (CSRF). This is fixed in version 16.1.7 by treating 'null' as an explicit origin value and enforcing host/origin checks unless 'null' is explicitly allowlisted in experimental.serverActions.allowedOrigins. If upgrading is not immediately possible, add CSRF tokens for sensitive Server Actions, prefer SameSite=Strict on sensitive auth cookies, and/or do not allow 'null' in serverActions.allowedOrigins unless intentionally required and additionally protected.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nextnpm
>= 16.0.1, < 16.1.716.1.7

Affected products

3
  • Vercel/Next.js2 versions
    cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*range: >=16.0.1,<16.1.7
    • (no CPE)range: >= 16.0.1, < 16.1.7
  • ghsa-coords
    Range: >= 16.0.1, < 16.1.7

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.

CVE-2026-27978 · Medium · VYPR