pkg:npm/next
共 47 筆 CVECRITICAL1HIGH16MEDIUM18LOW4
✅ 檢查你的版本
所有已知漏洞
- >= 13.0.0, < 13.5.9
- HIGH8.6CVE-2026-44578Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades>= 13.4.13, < 15.5.16
- HIGH8.1CVE-2026-44574Next.js has a Middleware / Proxy bypass through dynamic route parameter injection>= 15.4.0, < 15.5.16
- HIGH7.5CVE-2026-45109Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up>= 15.2.0, < 15.5.18
- HIGH7.5CVE-2026-44579Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components>= 15.0.0, < 15.5.16
- HIGH7.5CVE-2026-44575Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes>= 15.2.0, < 15.5.16
- HIGH7.5CVE-2026-44573Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n>= 12.2.0, < 15.5.16
- >= 15.0.4-canary.51, < 15.1.8
- >= 9.5.5, < 14.2.15
- >= 13.5.1, < 13.5.7
- >= 13.3.1, < 13.5.0
- >= 13.4.0, < 14.1.1
- >= 13.4.0, < 13.5.1
- >= 12.0.0, < 12.0.5
- >= 10.0.0, < 11.1.1
- >= 1.0.0, < 4.2.3
- >= 1.0.0, < 2.4.1
- >= 0.9.9, < 11.1.0
- >= 0.9.9, < 14.2.32
- >= 0.9.9, < 14.2.31
- MEDIUM6.1CVE-2026-44580Next.js has cross-site scripting in beforeInteractive scripts with untrusted input>= 13.0.0, < 15.5.16
- MEDIUM6.1CVE-2018-18282Next.js has cross site scripting (XSS) vulnerability via the 404 or 500 /_error page>= 7.0.0, < 7.0.2
- >= 10.0.0, < 15.5.16
- >= 16.0.0-beta.0, < 16.1.5
- MEDIUM5.9CVE-2025-59471Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration>= 10.0.0, < 15.5.10
- >= 10.0.0, < 14.2.7
- MEDIUM5.9CVE-2022-23646Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.1.0>= 10.0.0, < 12.1.0
- >= 12.0.0, < 12.0.9
- >= 14.2.0, < 15.5.16
- >= 13.0.0, < 13.5.8
- >= 12.2.3, < 12.2.4
- MEDIUM4.7CVE-2026-44581Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces>= 13.4.0, < 15.5.16
- >= 9.5.0, < 9.5.4
- >= 0.9.9, < 9.3.2
- >= 0.9.9, < 14.2.31
- >= 12.2.0, < 15.5.16
- LOW3.7CVE-2026-44582Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting>= 13.4.6, < 15.5.16
- >= 15.3.0, < 15.3.3
- >= 0.9.9, < 14.2.24
- >= 16.0.0-beta.0, < 16.1.7
- >= 16.0.0-beta.0, < 16.1.7
- >= 16.0.1, < 16.1.7
- >= 16.0.1, < 16.1.7
- >= 16.0.1, < 16.1.7
- >= 15.0.0, < 15.2.2
- >= 12.3.5, < 12.3.6
- >= 0.9.9, < 13.4.20-canary.13