CVE-2026-27977Disclosure(vercel / next.js)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `allowedDevOrigins` is configured, allowing privacy-sensitive/opaque contexts (for example sandboxed documents) to connect unexpectedly. If a dev server is reachable from attacker-controlled content, an attacker may be able to connect to the HMR websocket channel and interact with dev websocket traffic. This affects development mode only. Apps without a configured `allowedDevOrigins` still allow connections from any origin. The issue is fixed in version 16.1.7 by validating `Origin: null` through the same cross-site origin-allowance checks used for other origins. If upgrading is not immediately possible, do not expose `next dev` to untrusted networks and/or block websocket upgrades to `/_next/webpack-hmr` when `Origin` is `null` at the proxy.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1385

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-18); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-18: 2Mentions · 2026-03-19: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 103-1803-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-182
Disclosure1General1
2026-03-191
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27977 Next.js Development Mode WebSocket Origin Validation Vulnerability in Versions 16.0.1-16.1.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27977

    Post summary

    A brief disclosure of a WebSocket origin validation vulnerability in Next.js Development Mode (versions 16.0.1‑16.1.6); no PoC, exploit, active exploitation, or patch details are provided.

    0000136
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-27977 📊 Severity: 2.3 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-27977 #CVE-2026-27977 #CVE #Low  #CyberSecurity #InfoSec https://t.co/OE327KfvEh

    Post summary

    The tweet announces CVE‑2026‑27977 with a low CVSS score (2.3) but offers no additional technical details, exploits, or patch information.

    0000040
    104 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27977 Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection fo… https://www.cve.org/CVERecord?id=CVE-2026-27977

    Post summary

    The post merely references CVE‑2026‑27977, notes affected Next.js versions, and links to the CVE record, offering no further technical or mitigation details.

    00000122
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more