What is CVE-2026-64649?
CVE-2026-64649 is a Server-Side Request Forgery (SSRF) vulnerability in the Next.js framework, affecting versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10. An attacker can redirect outgoing requests from a Server Action to a malicious host. Immediate framework update is required.
Azərbaycanca: CVE-2026-64649 Next.js frameworkündə Server-Side Request Forgery (SSRF) zəifliyidir. 14.1.1-15.5.20 və 16.0.0-16.2.10 versiyalarını təsir edir, Server Action ilə edilən yönləndirmələrdə hücumçu sorğunu zərərli hosta yönləndirə bilər. Təcili framework yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Next.js are affected by CVE-2026-64649?
CVE-2026-64649 affects Next.js versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10.
How can I protect against the SSRF vulnerability in CVE-2026-64649?
To protect against this vulnerability, an immediate framework update for Next.js is required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.