What is CVE-2026-64641?
In Next.js versions using App Router with Server Actions, specially crafted requests can cause excessive CPU consumption, blocking the processing of further requests. This vulnerability affects versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10. Updating Next.js to a patched version is recommended for affected systems.
Azərbaycanca: Next.js-in App Router ilə Server Action istifadə edən versiyalarında xüsusi hazırlanmış sorğular həddindən artıq CPU istifadəsinə səbəb olur və digər sorğuların işlənməsini bloklayır. Bu zəiflik 13.0.0-15.5.20 və 16.0.0-16.2.10 versiyalarına təsir edir. Təsirlənən sistemlərdə Next.js-i ən son patching versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
I'm using Next.js version 15.3.4 with App Router. Am I affected by CVE-2026-64641?
Yes, since Next.js versions 13.0.0 through 15.5.20 are affected, version 15.3.4 is vulnerable. You should update your system to a patched version.
How does CVE-2026-64641 impact Next.js systems using Server Actions?
Specially crafted requests can cause excessive CPU consumption, blocking the processing of further requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.