CVE-2026-64641: Next.js: Denial of Service in App Router using Server Actions
Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.
References
- github.com/advisories/GHSA-m99w-x7hq-7vfj
- github.com/vercel/next.js/commit/019628571641dec57aaf349ba0c360e3964e6f12
- github.com/vercel/next.js/pull/96013
- github.com/vercel/next.js/releases/tag/v15.5.21
- github.com/vercel/next.js/releases/tag/v16.2.11
- github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj
- nvd.nist.gov/vuln/detail/CVE-2026-64641
Code Behaviors & Features
Detect and mitigate CVE-2026-64641 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →