CVE-2026-27979Disclosure(vercel / next.js)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch vercel next.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies without consistently enforcing `maxPostponedStateSize` in certain setups. The previous mitigation protected minimal-mode deployments, but equivalent non-minimal deployments remained vulnerable to the same unbounded postponed resume-body buffering behavior. In applications using the App Router with Partial Prerendering capability enabled (via `experimental.ppr` or `cacheComponents`), an attacker could send oversized `next-resume` POST payloads that were buffered without consistent size enforcement in non-minimal deployments, causing excessive memory usage and potential denial of service. This is fixed in version 16.1.7 by enforcing size limits across all postponed-body buffering paths and erroring when limits are exceeded. If upgrading is not immediately possible, block requests containing the `next-resume` header, as this is never valid to be sent from an untrusted client.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-18); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-18: 2Mentions · 2026-03-19: 2Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 203-1803-19
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-182
Disclosure1Patch1
2026-03-192
Disclosure1General1
Full discourse4 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-27979 📊 Severity: 6.9 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-27979 #CVE-2026-27979 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/umIGt0xzLO

    Post summary

    The tweet announces the new CVE-2026-27979 with a medium severity score of 6.9 and unspecified product impact, but provides no further technical, exploit, or mitigation details.

    0000029
    104 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-27979 - vercel - next.js - https://www.redpacketsecurity.com/cve-alert-cve-2026-27979-vercel-next-js/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-27979 #vercel #next-js

    Post summary

    A CVE alert for CVE‑2026‑27979 targeting Vercel's Next.js is referenced via a link, but no additional details about exploitation, patches, or technical specifics are provided.

    0000072
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27979 Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: … https://www.cve.org/CVERecord?id=CVE-2026-27979

    Post summary

    The snippet indicates that Next.js versions 16.0.1 through 16.1.6 are vulnerable when a request includes a 'next-resume' header, but it offers no proof of concept, exploit code, patch, or evidence of active exploitation.

    00000114
    56.7K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-27979: POST requests with ‘next-resume: 1’ can exhaust memory in Next.js sites using Partial Prerendering, leading to DoS. Upgrade to 16.1.7 or block that header. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-27979 #Nextjs #infosec #webdev

    Post summary

    The advisory alerts that POST requests with ‘next-resume: 1’ can exhaust memory and cause a DoS in Next.js, recommending users upgrade to version 16.1.7 or block the header.

    0000063
    55 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more