Important severity8.2OSV Advisory· Published Jul 27, 2026
next: Next.js: Server-Side Request Forgery via malicious host redirection in Server Actions
CVE-2026-64649
Description
next: Next.js: Server-Side Request Forgery via malicious host redirection in Server Actions
Affected products
2Patches
Vulnerability mechanics
News mentions
2- Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 StoriesCyber Security News · Jul 26, 2026
- Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS AttacksCyber Security News · Jul 23, 2026