CVE-2026-27978Patch(vercel / next.js)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vercel next.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a "missing" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing actions with victim credentials (CSRF). This is fixed in version 16.1.7 by treating `'null'` as an explicit origin value and enforcing host/origin checks unless `'null'` is explicitly allowlisted in `experimental.serverActions.allowedOrigins`. If upgrading is not immediately possible, add CSRF tokens for sensitive Server Actions, prefer `SameSite=Strict` on sensitive auth cookies, and/or do not allow `'null'` in `serverActions.allowedOrigins` unless intentionally required and additionally protected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-03-18); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Mentions · 2026-03-23: 1Mentions · 2026-05-03: 1Mentions · 2026-05-04: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-05-03: 1Technical Details · 2026-03-18: 1Technical Details · 2026-05-03: 103-1803-1903-2305-0305-04
Signal classification3 categories
Patch
240.0%
General
240.0%
Disclosure
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-181
Patch1
2026-03-191
General1
2026-03-231
Patch1
2026-05-031
Disclosure1
2026-05-041
General1
Full discourse5 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-26268 2 - CVE-2026-27978 3 - CVE-2026-31431 4 - CVE-2026-33825 5 - CVE-2026-35414 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVEs but provides no additional information on exploitation, patches, or technical specifics.

    00030187
    1.7K followersView on X
  • Cel Quintero 𝕏@Cel_Metal_
    Disclosure

    This happened to me too but with @vercel. Reported on March 15 2026, 6:20 AM UTC: CSRF bypass in Next.js Server Actions via Origin: null. Closed as duplicate at 6:36 AM — 16 minutes, no technical review. Three days later: GHSA-mq59-m269-xvcx + CVE-2026-27978 published. Same terminology, same attack vector, same code location, same fix. I escalated to HackerOne Support. They told me report decisions are up to the program team. @vercel you are the program team. I’d appreciate a direct review @vercel

    Post summary

    The post reports a CSRF bypass in Next.js Server Actions, noting it was flagged on HackerOne, later published as CVE-2026-27978 with an existent fix, but no PoC, exploit code, or evidence of active exploitation is included.

    00000109
    1.8K followersView on X
  • Cel Quintero 𝕏@Cel_Metal_
    Patch

    🚨URGENT: Report #3605642 closed 16 min no credit – verbatim to Next.js patch (CVE-2026-27978 / GHSA-mq59-m269-xvcx). Open on @hackerone @vercel @nextjs mediation needed!#Nextjs https://github.com/vercel/next.js/security/advisories/GHSA-mq59-m269-xvcx

    Post summary

    The tweet announces that CVE-2026-27978 in Next.js has been patched, referencing a GitHub security advisory, but does not provide a PoC, exploit, or technical details of the vulnerability.

    0000053
    1.8K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-27978 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-27978 #CVE-2026-27978 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/CyXQk4E5e9

    Post summary

    The tweet announces a newly identified CVE with medium severity but provides neither technical specifics nor evidence of exploitation or patches.

    0000034
    104 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-27978 Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a "missin… https://www.cve.org/CVERecord?id=CVE-2026-27978

    Post summary

    The note identifies a vulnerability in Next.js affecting versions before 16.1.7, indicating a fix in newer releases and providing minimal technical detail.

    00000108
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more