Skip to content
ThreatCluster

Critical DoS Vulnerability in Next.js Allows Unauthenticated Server Crashes

First seen 27 Nov 2025, 15:36 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Security researchers have identified a critical denial-of-service vulnerability in Next.js that enables unauthenticated attackers to crash servers with a single request. This vulnerability poses a significant risk to web applications built on the Next.js framework, potentially leading to service disruptions for affected users.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)