Vercel has patched three high-severity vulnerabilities in Next.js that could allow server-side request forgery (SSRF) and, in a narrower configuration, bypass middleware-based authentication. The flaws are tracked as CVE-2026-64645, CVE-2026-64649, and CVE-2026-64642, each rated CVSS 8.3, and affect multiple supported branches of the framework. According to the advisory coverage, the SSRF issues can be triggered under specific configurations, while the authentication bypass affects deployments using the App Router and Turbopack in a limited scenario.
The issues were fixed in Next.js 16.2.11 and 15.5.21, with no public proof-of-concept or confirmed in-the-wild exploitation reported at publication time. Defenders are advised to upgrade promptly, avoid user-controlled external destination hostnames, validate Host and X-Forwarded-Host headers, and enforce authorization checks in server-side page logic rather than relying solely on middleware protections.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Vercel fixed three high-severity Next.js flaws: CVE-2026-64645 and CVE-2026-64649, which can enable SSRF in specific configurations, and CVE-2026-64642, which can allow middleware-based authentication bypass in a narrower App Router and Turbopack scenario. The fixes were released in Next.js versions 16.2.11 and 15.5.21.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.