
[CIVN-2026-0394] Server-Side Request Forgery (SSRF) Vulnerability in Next.js
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Server-Side Request Forgery (SSRF) Vulnerability in Next.js
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Next.js version 12.0.0 or higher and prior to 15.5.21
Next.js version 16.0.0 or higher and prior to 16.2.11
Overview
A Server-Side Request Forgery (SSRF) vulnerability exists in the Next.js framework. An unauthenticated remote attacker may exploit this vulnerability to cause the server to issue requests to arbitrary internal or external hosts or perform Open Redirect attacks.
Target Audience:
Organizations developing or hosting web applications using the Next.js framework.
Risk Assessment:
High risk of unauthorized access to internal network resources and disclosure of sensitive information.
Impact Assessment:
Potential High impact on Confidentiality of the System.
Description
Next.js is a React-based web application framework used for building server-rendered and full-stack web applications. Next.js framework is affected by the Server-Side Request Forgery (SSRF) vulnerability.
This vulnerability exists due to improper validation of request-controlled inputs during the processing of rewrites() and redirects() configuration rules where destination hostname is dynamically generated from request-controlled inputs.
An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted requests that manipulate the destination hostname to an arbitrary host instead of the intended destination.
Successful exploitation could allow the attacker to perform Server-Side Request Forgery (SSRF), resulting in unauthorized access to internal or external network resources in applications using the affected rewrites() configurations, or perform Open Redirect attacks in applications using the affected redirects() configurations.
Solution
Apply appropriate Updates and steps as mentioned by the vendor:
https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4
Vendor Information
https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4
References
https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4
CVE Name
CVE-2026-64645
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp0mR0ACgkQ3jCgcSdc
ys/Xyg/9Gz5WxxJZIJWlEuMntOhaT1HmroYc4R7ZXW0nRA15jQOmdlik10MehE05
2gdwmzhLoSfnSW1xJ3QQq9muT1nUVLZWFYvh4l4x4JCgOMgC0M9ECjrPVW33a6+G
iteXFSyICSRVQqf+OZOrWImnslBhhp3IeXagTgS17IHt8Lm01emi5ej4TLenMROr
qrC/qNx72DGdwhXJOaA+gnkJeRGJwdMq0MFPkHfSO0PuaAA8YMBPFgrzaUpryRRn
XohQ6b3j4CxMhSqGpubQiBFPle2JZhAtj9KQCC7ME8bvt4xOPZZzImX72K/9PyLX
vEq/hamXiTyJv7JaVCP/35kK5U30L7PYIdt2C7Y7MnTANLKGd3EiiajoruYxNJvy
vdFAq4NFWCgJoP+5DO8hKboB2hZK/IEQt+vzC0xp6VixbE1+AAZqArUwTxujIpAR
tcVwqt12hBSQA+txl/m1R2ojHrvJPg49j6c6A1D72UMZ82G6Y1vqDNWSf8w15nC+
strRUPjdhDhYWtX4hXiF00fd4b2MnOaeXzNZc6FXHG9JKH3Xs6TyZlC0N1gthPTR
DztxblEA4f1jecoxxRS8rVYVPL/54BMpK6AKYjlQZ2tCHtmHVfoSzjMCjc5nQ+6J
Wmd4LrSsOwiwY4KGEOLBl7ivPk1fTtMJ3siLRC0Q21guYAyNuQU=
=+Rga
—–END PGP SIGNATURE—–


