VYPR
Important severity7.5OSV Advisory· Published Jul 27, 2026

next: Next.js: Denial of Service via excessive memory consumption in Server Actions

CVE-2026-64646

Description

next: Next.js: Denial of Service via excessive memory consumption in Server Actions

Affected products

2
  • Vercel/Next.jsOSV2 versions
    v16.2.10, v16.2.9, v16.2.8, …+ 1 more
    • (no CPE)range: v16.2.10, v16.2.9, v16.2.8, …
    • (no CPE)

Patches

Vulnerability mechanics

News mentions

1