Medium severity6.1OSV Advisory· Published Jul 27, 2026· Updated Jul 29, 2026
CVE-2026-64645
CVE-2026-64645
Description
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A redirects() rule configured this way is vulnerable to an Open Redirect. This issue has been fixed in versions 15.5.21 and 16.2.11.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nextnpm | >= 12.0.0, < 15.5.21 | 15.5.21 |
nextnpm | >= 16.0.0, < 16.2.11 | 16.2.11 |
Affected products
17- osv-coords14 versionspkg:apk/chainguard/langfuse-fips-2pkg:apk/chainguard/langfuse-2pkg:apk/chainguard/homepagepkg:apk/chainguard/keep-uipkg:apk/wolfi/jitsucom-jitsu-consolepkg:apk/wolfi/langfuse-3pkg:apk/wolfi/langfuse-3-workerpkg:apk/chainguard/jitsucom-jitsu-consolepkg:apk/chainguard/keep-ui-fipspkg:apk/chainguard/langfuse-3-workerpkg:apk/chainguard/langfuse-fips-3-workerpkg:apk/chainguard/peerdb-uipkg:apk/chainguard/langfuse-3pkg:apk/chainguard/langfuse-fips-3
< 2.95.12-r38+ 13 more
- (no CPE)range: < 2.95.12-r38
- (no CPE)range: < 2.95.12-r35
- (no CPE)range: < 1.13.2-r9
- (no CPE)range: < 0.54.2-r1
- (no CPE)range: < 2.11.0-r30
- (no CPE)range: < 3.224.1-r0
- (no CPE)range: < 3.224.1-r0
- (no CPE)range: < 2.11.0-r30
- (no CPE)range: < 0.54.2-r1
- (no CPE)range: < 3.224.1-r0
- (no CPE)range: < 3.224.1-r0
- (no CPE)range: < 0.37.3-r1
- (no CPE)range: < 3.224.1-r0
- (no CPE)range: < 3.224.1-r0
Patches
Vulnerability mechanics
References
6- github.com/vercel/next.js/commit/35f501357e9b0fe7c950b0d6aa8fcf5343f707e9nvdPatchWEB
- github.com/vercel/next.js/commit/d3033266c6dff23f7be71e19341fe3a8c6e2c599nvdPatchWEB
- github.com/advisories/GHSA-p9j2-gv94-2wf4ghsaADVISORY
- github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4nvdMitigationVendor AdvisoryWEB
- github.com/vercel/next.js/releases/tag/v15.5.21nvdProductRelease NotesWEB
- github.com/vercel/next.js/releases/tag/v16.2.11nvdProductRelease NotesWEB
News mentions
4- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026
- Next.js: Nine SSRF, Auth Bypass, and DoS Vulnerabilities Patched TogetherVypr Intelligence · Jul 27, 2026
- Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 StoriesCyber Security News · Jul 26, 2026
- Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS AttacksCyber Security News · Jul 23, 2026