Moderate severity5.3OSV Advisory· Published Jul 27, 2026
next: Next.js: Information disclosure via Server Action ID exposure
CVE-2026-64643
Description
next: Next.js: Information disclosure via Server Action ID exposure
Affected products
2Patches
Vulnerability mechanics
News mentions
1- Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS AttacksCyber Security News · Jul 23, 2026