Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
655912
AlmaLinux
4783
Alpaquita
9505
Alpine
4125
Android
3262
Azure Linux
12016
BellSoft Hardened Containers
466
Bitnami
7856
Chainguard
6237
CleanStart
815
CRAN
14
crates.io
2379
Debian
56026
Echo
3980
GHC
3
GIT
81555
GitHub Actions
50
Go
6847
Hackage
30
Hex
89
Julia
838
Linux
15361
Mageia
5916
Maven
6470
MinimOS
41010
npm
218267
NuGet
1679
opam
12
openEuler
6749
openSUSE
12773
OSS-Fuzz
3876
Packagist
6248
Pub
11
PyPI
19168
Red Hat
19858
Rocky Linux
3058
Root
14008
RubyGems
1961
SUSE
20561
SwiftURL
51
Ubuntu
54006
VSCode
18
Wolfi
3975
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-3749
npm/@webapp-next/store
Malicious code in @webapp-next/store (npm)
3 days ago
No fix available
GHSA-26hh-7cqf-hhc6
npm/next
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
6 days ago
Fix available
Severity - 7.5 (High)
GHSA-3g8h-86w9-wvmq
npm/next
Next.js's Middleware / Proxy redirects can be cache-poisoned
6 days ago
Fix available
Severity - 3.7 (Low)
GHSA-ffhc-5mcf-pf4q
npm/next
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
6 days ago
Fix available
Severity - 4.7 (Medium)
GHSA-vfv6-92ff-j949
npm/next
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
6 days ago
Fix available
Severity - 3.7 (Low)
GHSA-gx5p-jg67-6x7h
npm/next
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
6 days ago
Fix available
Severity - 6.1 (Medium)
GHSA-mg66-mrh9-m8jx
npm/next
Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components
6 days ago
Fix available
Severity - 7.5 (High)
GHSA-h64f-5h5j-jqjh
npm/next
Next.js has a Denial of Service in the Image Optimization API
6 days ago
Fix available
Severity - 5.9 (Medium)
GHSA-c4j6-fc7j-m34r
npm/next
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
6 days ago
Fix available
Severity - 8.6 (High)
GHSA-wfc6-r584-vfw7
npm/next
Next.js vulnerable to cache poisoning in React Server Component responses
6 days ago
Fix available
Severity - 5.4 (Medium)
GHSA-267c-6grr-h53f
npm/next
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
6 days ago
Fix available
Severity - 7.5 (High)
GHSA-492v-c6pp-mqqv
npm/next
Next.js has a Middleware / Proxy bypass through dynamic route parameter injection
6 days ago
Fix available
Severity - 8.1 (High)
GHSA-36qx-fr4f-26g5
npm/next
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
6 days ago
Fix available
Severity - 7.5 (High)
GHSA-8h8q-6873-q5fj
npm/next
Next.js Vulnerable to Denial of Service with Server Components
11 May
Fix available
Severity - 7.5 (High)
GHSA-2xx6-qf7x-grqh
npm/@jswork/next-npm-version
next-npm-version is vulnerable to Command injection
07 May
No fix available
Severity - 9.8 (Critical)
GHSA-4c35-wcg5-mm9h
npm/next-intl
next-intl has prototype pollution with
`
experimental.messages.precompile
`
via attacker-controlled translation catalog keys
06 May
Fix available
Severity - 4.2 (Medium)
Load more...
npm - OSV