[CIVN-2026-0394] Server-Side Request Forgery (SSRF) Vulnerability in Next.js

By Published On: August 6, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Server-Side Request Forgery (SSRF) Vulnerability in Next.js


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Next.js version 12.0.0 or higher and prior to 15.5.21

Next.js version 16.0.0 or higher and prior to 16.2.11

Overview


A Server-Side Request Forgery (SSRF) vulnerability exists in the Next.js framework. An unauthenticated remote attacker may exploit this vulnerability to cause the server to issue requests to arbitrary internal or external hosts or perform Open Redirect attacks.


Target Audience:

Organizations developing or hosting web applications using the Next.js framework.


Risk Assessment:

High risk of unauthorized access to internal network resources and disclosure of sensitive information.


Impact Assessment:

Potential High impact on Confidentiality of the System.


Description


Next.js is a React-based web application framework used for building server-rendered and full-stack web applications. Next.js framework is affected by the Server-Side Request Forgery (SSRF) vulnerability.


This vulnerability exists due to improper validation of request-controlled inputs during the processing of rewrites() and redirects() configuration rules where destination hostname is dynamically generated from request-controlled inputs.


An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted requests that manipulate the destination hostname to an arbitrary host instead of the intended destination.


Successful exploitation could allow the attacker to perform Server-Side Request Forgery (SSRF), resulting in unauthorized access to internal or external network resources in applications using the affected rewrites() configurations, or perform Open Redirect attacks in applications using the affected redirects() configurations.


Solution


Apply appropriate Updates and steps as mentioned by the vendor:

https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4



Vendor Information


 

https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4


References


 

https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4


CVE Name

CVE-2026-64645




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp0mR0ACgkQ3jCgcSdc

ys/Xyg/9Gz5WxxJZIJWlEuMntOhaT1HmroYc4R7ZXW0nRA15jQOmdlik10MehE05

2gdwmzhLoSfnSW1xJ3QQq9muT1nUVLZWFYvh4l4x4JCgOMgC0M9ECjrPVW33a6+G

iteXFSyICSRVQqf+OZOrWImnslBhhp3IeXagTgS17IHt8Lm01emi5ej4TLenMROr

qrC/qNx72DGdwhXJOaA+gnkJeRGJwdMq0MFPkHfSO0PuaAA8YMBPFgrzaUpryRRn

XohQ6b3j4CxMhSqGpubQiBFPle2JZhAtj9KQCC7ME8bvt4xOPZZzImX72K/9PyLX

vEq/hamXiTyJv7JaVCP/35kK5U30L7PYIdt2C7Y7MnTANLKGd3EiiajoruYxNJvy

vdFAq4NFWCgJoP+5DO8hKboB2hZK/IEQt+vzC0xp6VixbE1+AAZqArUwTxujIpAR

tcVwqt12hBSQA+txl/m1R2ojHrvJPg49j6c6A1D72UMZ82G6Y1vqDNWSf8w15nC+

strRUPjdhDhYWtX4hXiF00fd4b2MnOaeXzNZc6FXHG9JKH3Xs6TyZlC0N1gthPTR

DztxblEA4f1jecoxxRS8rVYVPL/54BMpK6AKYjlQZ2tCHtmHVfoSzjMCjc5nQ+6J

Wmd4LrSsOwiwY4KGEOLBl7ivPk1fTtMJ3siLRC0Q21guYAyNuQU=

=+Rga

—–END PGP SIGNATURE—–

Share this article