{"package":"next","ecosystem":"npm","latest_version":"16.3.6","description":"The React Framework","license":"MIT","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://nextjs.org","repository":"https://github.com/vercel/next.js","downloads_weekly":42734285,"health":{"score":60,"risk":"moderate","breakdown":{"maintenance":25,"popularity":20,"security":11,"maturity":15,"community":14,"popularity_floor":0},"deprecated":false,"max_score":100},"vulnerabilities":{"count":5,"critical":0,"high":2,"medium":2,"low":1,"details":[{"vuln_id":"CVE-2025-59472","severity":"medium","summary":"Next.js has Unbounded Memory Consumption via PPR Resume Endpoint ","affected_versions":">=16.0.0-beta.0,<16.1.5|>=15.0.0-canary.0,<=15.0.0-canary.205|>=15.0.1-canary.0,<=15.0.1-canary.3|>=15.0.2-canary.0,<=15.0.2-canary.11|>=15.0.3-canary.0,<=15.0.3-canary.9|>=15.0.4-canary.0,<=15.0.4-canary.52|>=15.1.1-canary.0,<=15.1.1-canary.27|>=15.2.0-canary.0,<=15.2.0-canary.77|>=15.2.1-canary.0,<=15.2.1-canary.6|>=15.2.2-canary.0,<=15.2.2-canary.7|>=15.3.0-canary.0,<=15.3.0-canary.46|>=15.3.1-canary.0,<=15.3.1-canary.15|>=15.4.0-canary.0,<=15.4.0-canary.130|>=15.4.2-canary.0,<=15.4.2-canary.56|>=15.5.1-canary.0,<=15.5.1-canary.39|>=15.6.0-canary.0,<15.6.0-canary.61","fixed_version":"15.6.0-canary.61","source":"osv","published_at":"2026-01-28T15:20:55Z"},{"vuln_id":"GHSA-5j59-xgg2-r9c4","severity":"high","summary":"Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up","affected_versions":">=13.3.1-canary.0,<14.2.35|>=15.0.6,<15.0.7|>=15.1.10,<15.1.11|>=15.2.7,<15.2.8|>=15.3.7,<15.3.8|>=15.4.9,<15.4.10|>=15.5.8,<15.5.9|>=15.6.0-canary.59,<15.6.0-canary.60|>=16.0.9,<16.0.10|>=16.1.0-canary.17,<16.1.0-canary.19","fixed_version":"16.1.0-canary.19","source":"osv","published_at":"2025-12-12T17:21:57Z"},{"vuln_id":"CVE-2023-46298","severity":"low","summary":"Next.js missing cache-control header may lead to CDN caching empty reply","affected_versions":">=0.9.9,<13.4.20-canary.13","fixed_version":"13.4.20-canary.13","source":"osv","published_at":"2023-10-22T03:30:23Z"},{"vuln_id":"GHSA-mwv6-3258-q52c","severity":"high","summary":"Next Vulnerable to Denial of Service with Server Components","affected_versions":">=13.3.0,<14.2.34|>=15.0.0-canary.0,<15.0.6|>=15.1.1-canary.0,<15.1.10|>=15.2.0-canary.0,<15.2.7|>=15.3.0-canary.0,<15.3.7|>=15.4.0-canary.0,<15.4.9|>=15.5.1-canary.0,<15.5.8|>=15.6.0-canary.0,<15.6.0-canary.59|>=16.0.0-beta.0,<16.0.9|>=16.1.0-canary.0,<16.1.0-canary.17","fixed_version":"16.1.0-canary.17","source":"osv","published_at":"2025-12-11T22:49:27Z"},{"vuln_id":"GHSA-w37m-7fhw-fmv9","severity":"medium","summary":"Next Server Actions Source Code Exposure ","affected_versions":">=15.0.0-canary.0,<15.0.6|>=15.1.1-canary.0,<15.1.10|>=15.2.0-canary.0,<15.2.7|>=15.3.0-canary.0,<15.3.7|>=15.4.0-canary.0,<15.4.9|>=15.5.1-canary.0,<15.5.8|>=15.6.0-canary.0,<15.6.0-canary.59|>=16.0.0-beta.0,<16.0.9|>=16.1.0-canary.0,<16.1.0-canary.17","fixed_version":"16.1.0-canary.17","source":"osv","published_at":"2025-12-11T22:49:56Z"}]},"versions":{"latest":"16.3.6","total_count":3949,"recent":["16.4.0-canary.23","16.4.0-canary.24","16.4.0-canary.25","16.4.0-canary.26","16.3.5","16.4.0-canary.27","16.4.0-canary.28","16.4.0-canary.29","16.4.0-canary.30","16.4.0-canary.31","16.4.0-canary.32","16.4.0-canary.33","16.4.0-canary.34","16.4.0-canary.35","16.4.0-canary.36","16.4.0-canary.37","16.4.0-canary.38","16.3.6","15.5.26","16.4.0-canary.39"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":4,"first_published":"2011-07-11T11:00:45.416Z","last_published":"2026-09-22T16:19:00.458Z","dependencies_count":6,"dependencies":["postcss","@next/env","styled-jsx","@swc/helpers","caniuse-lite","baseline-browser-mapping"]},"github_stats":{"stars":142414,"forks":32604,"open_issues":3461,"is_archived":false,"pushed_at":"2026-09-23T10:49:12Z","subscribers_count":1631},"bundle":null,"typescript":{"score":10,"has_types":true,"types_source":"bundled","types_package":null},"known_issues":{"bugs_count":2,"bugs_severity":{"medium":1,"low":1},"status_breakdown":{"closed":2},"link":"/api/bugs/npm/next","scope":"all","details":[{"title":"next/image with remotePatterns and query strings returns 404 on edge","severity":"medium","status":"closed","affected_version":"15.0.0","fixed_version":"15.0.1","url":"https://github.com/vercel/next.js/issues/71755"},{"title":"Server Action with useActionState loses state on navigation","severity":"low","status":"closed","affected_version":"15.1.0 - 15.1.2","fixed_version":"15.1.3","url":"https://github.com/vercel/next.js/issues/74523"}]},"historical_compromise":null,"recommendation":{"action":"update_required","issues":["Moderate health score (60/100) — verify manually","2 high severity vulnerabilities"],"use_version":"16.3.6","version_hint":"Update to >= 16.1.0-canary.17 to fix known vulnerabilities","summary":"next@16.3.6 has vulnerabilities — update to latest"},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/npm/next","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/npm/next","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/npm/next","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate"},"_cache":"hit","_response_ms":0}