The React Framework
[email protected] has vulnerabilities — update to latest
Update to >= 16.1.0-canary.17 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | CVE-2025-59472 | Next.js has Unbounded Memory Consumption via PPR Resume Endpoint | 15.6.0-canary.61 |
| high | GHSA-5j59-xgg2-r9c4 | Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up | 16.1.0-canary.19 |
| low | CVE-2023-46298 | Next.js missing cache-control header may lead to CDN caching empty reply | 13.4.20-canary.13 |
| high | GHSA-mwv6-3258-q52c | Next Vulnerable to Denial of Service with Server Components | 16.1.0-canary.17 |
| medium | GHSA-w37m-7fhw-fmv9 | Next Server Actions Source Code Exposure | 16.1.0-canary.17 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/nextFirst published · 2011-07-11T11:00:45.416Z
Last updated · 2026-05-07T19:01:54.751Z