Summary
Next.js: Denial of Service in App Router using Server Actions
Advisory details
Impact
Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.
Workarounds
No workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.
References
- https://github.com/advisories/GHSA-m99w-x7hq-7vfj
- https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj
- https://github.com/vercel/next.js/pull/96013
- https://github.com/vercel/next.js/commit/019628571641dec57aaf349ba0c360e3964e6f12
- https://github.com/vercel/next.js/releases/tag/v15.5.21
- https://github.com/vercel/next.js/releases/tag/v16.2.11
Related vulnerabilities
All Supply chain →- MEDIUMCVE-2026-84310
pypdf: Possible long runtimes/large memory usage when retrieving outlines
- MEDIUMCVE-2026-84311
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
- MEDIUMCVE-2026-71852
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
- HIGHGHSA-7q9c-hpx7-9cwm
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
- CRITICALCVE-2026-73842
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
- MEDIUMCVE-2026-73557
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts