REDHAT-BUG-2477193: High severity Vercel Next.js vulnerability
Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are denied service. This vulnerability is fixed in 15.5.16 and 16.2.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
next.jsto a version that resolves this vulnerability.Fixed in 15.5.16 - Upgrade
Upgrade
next.jsto a version that resolves this vulnerability.Fixed in 16.2.5
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2477193?
The severity of REDHAT-BUG-2477193 is high with a score of 7.
How does the vulnerability REDHAT-BUG-2477193 affect applications?
REDHAT-BUG-2477193 can lead to connection exhaustion through crafted POST requests when using Partial Prerendering with the Cache Components feature.
What versions of Next.js are affected by REDHAT-BUG-2477193?
Versions of Vercel Next.js prior to 15.5.16 and 16.2.5 are affected by REDHAT-BUG-2477193.
How can I mitigate the effects of REDHAT-BUG-2477193?
Mitigation for REDHAT-BUG-2477193 involves upgrading to Next.js versions 15.5.16 or 16.2.5 or later.
When was REDHAT-BUG-2477193 published?
REDHAT-BUG-2477193 was published on May 13, 2026.