CVE-2026-64646: Next.js: Unbounded Server Action payload in Edge runtime
Requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime
References
- github.com/advisories/GHSA-4c39-4ccg-62r3
- github.com/vercel/next.js/commit/57c31f724d746e86a9e8b92aa8be538a922446a4
- github.com/vercel/next.js/commit/9a4651e754f70b12e397694ffc41f44c3ba8cc17
- github.com/vercel/next.js/releases/tag/v15.5.21
- github.com/vercel/next.js/releases/tag/v16.2.11
- github.com/vercel/next.js/security/advisories/GHSA-4c39-4ccg-62r3
- nvd.nist.gov/vuln/detail/CVE-2026-64646
Code Behaviors & Features
Detect and mitigate CVE-2026-64646 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →