Important severity7.5OSV Advisory· Published Jul 27, 2026
next: Next.js: Denial of Service via excessive memory consumption in Server Actions
CVE-2026-64646
Description
next: Next.js: Denial of Service via excessive memory consumption in Server Actions
Affected products
2Patches
Vulnerability mechanics
News mentions
1- Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS AttacksCyber Security News · Jul 23, 2026