Vercel has released a broad set of security fixes for Next.js and related React Server Components, addressing more than a dozen vulnerabilities affecting App Router deployments across versions 13.x through 16.x and React Server Components 19.x. The disclosures include denial of service, server-side request forgery, cross-site scripting, cache poisoning, and multiple middleware authorization bypass conditions. Among the most serious issues is CVE-2026-23870 (GHSA-8h8q-6873-q5fj), a high-severity denial-of-service flaw in React Flight deserialization that can be triggered through crafted requests to App Router Server Function endpoints, causing excessive CPU consumption; fixes were issued in Next.js 15.5.16 and 16.2.5. Vercel also disclosed CVE-2026-44578, a high-severity SSRF issue in self-hosted Node.js deployments via crafted WebSocket upgrade requests.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Vercel disclosed more than a dozen vulnerabilities affecting Next.js and related React Server Components, including middleware authorization bypass, SSRF, XSS, cache poisoning, and additional DoS issues. The advisories covered affected versions across Next.js 13.x through 16.x and React Server Components 19.x, with upgrade and mitigation guidance for users.
Vercel published a security advisory for CVE-2026-23870 / GHSA-8h8q-6873-q5fj, a denial-of-service issue in App Router deployments using vulnerable React Server Components packages. The company said crafted requests to Server Function endpoints could cause excessive CPU consumption and released fixes in Next.js 15.5.16 and 16.2.5.
Through April 2025, more GitHub projects released exploit code, scanners, and simulation environments for CVE-2025-29927. These references show broader public weaponization and testing support for the middleware bypass vulnerability.
Multiple GitHub repositories published proof-of-concept material for CVE-2025-29927, a Next.js middleware authorization bypass issue. The PoCs describe bypassing protections in Next.js middleware, including abuse of the x-middleware-subrequest header.
A GitHub repository published a Nuclei template for CVE-2025-29927, indicating public detection guidance for the Next.js middleware authorization bypass vulnerability. This is the earliest reference in the provided material tied to the flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
23 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.