CVE-2026-27980Disclosure(vercel / next.js)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch vercel next.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including eviction of least-recently-used entries when the limit is exceeded. Setting `maximumDiskCacheSize: 0` disables disk caching. If upgrading is not immediately possible, periodically clean `.next/cache/images` and/or reduce variant cardinality (e.g., tighten values for `images.localPatterns`, `images.remotePatterns`, and `images.qualities`).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-18); latest day: 2
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline7 mentions / 4d
01122Mentions · 2026-03-04: 1Mentions · 2026-03-18: 2Mentions · 2026-03-19: 2Mentions · 2026-03-27: 2Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-27: 103-0403-1803-1903-27
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
General
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-041
Disclosure1
2026-03-182
Disclosure1Patch1
2026-03-192
Disclosure1General1
2026-03-272
Disclosure1Patch1
Full discourse7 posts
  • AndrewMohawk⁽ⁿᵘˡˡ⁾@AndrewMohawk
    Disclosure

    @andrewmohawk Hi, sorry for the wait here. We're in the process of releasing a CVE for this under CVE-2026-27980 https://t.co/pzM7VInSkp

    Post summary

    The tweet announces the creation of CVE-2026-27980 but provides no technical details, PoC, exploitation information, or mitigations.

    20080560
    5.2K followersView on X
  • HeroDevs@herodevs
    Patch

    🚨 Two new CVEs impacting Next.js — What happens after support ends? CVE-2026-29057 and CVE-2026-27980 highlight a familiar pattern: → Request handling weaknesses that introduce unexpected behavior → Resource management issues that can impact application stability Both affect multiple versions of Next.js and for many teams those versions are already end-of-life. That’s the real risk → When a framework reaches EOL, fixes don’t follow. No patches. No updates. Just exposure. You can keep moving forward, but the threats don’t stop chasing. 👾 This is where teams get stuck: Migration takes time. Risk doesn’t wait. HeroDevs Never-Ending Support (NES) provides patched, drop-in replacements for EOL versions, so you can stay secure while planning your upgrade. Because the vulnerability isn’t just the CVE. It’s the software that will never be fixed. #NextJS #CVE #AppSec #OpenSourceSecurity #EOL #DevSecOps #HeroDevs

    Post summary

    The post warns that new CVEs in Next.js affect end‑of‑life versions and that vendors won’t patch them, while promoting HeroDevs’ patched drop‑in replacements as a workaround.

    10000184
    2.7K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-27980: Remote attackers can fill up disk via Next.js image optimization (v10–16.1.6), knocking sites offline. Upgrade to 16.1.7 or routinely clear .next/cache/images. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-27980 #Nextjs #infosec #webdev

    Post summary

    CVE-2026-27980 allows attackers to exhaust disk space by abusing Next.js image optimization; the advisory recommends upgrading to v16.1.7 or clearing the cache as a mitigation.

    0001087
    55 followersView on X
  • HeroDevs@herodevs
    Disclosure

    Learn more 🔗 https://www.herodevs.com/blog-posts/cve-2026-29057-and-cve-2026-27980-two-new-vulnerabilities-affecting-end-of-life-next-js

    Post summary

    The text links to a blog post that announces two new CVEs affecting end‑of‑life Next.js, but provides no further details.

    0000086
    2.7K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-27980 📊 Severity: 6.9 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-27980 #CVE-2026-27980 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/7HETgJQ9tY

    Post summary

    The tweet merely announces CVE-2026-27980 as a medium severity vulnerability affecting multiple unspecified products, providing minimal technical details with no exploitation or patch information.

    0000037
    104 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-27980 - vercel - next.js - https://www.redpacketsecurity.com/cve-alert-cve-2026-27980-vercel-next-js/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-27980 #vercel #next-js

    Post summary

    A CVE alert references CVE-2026-27980 for Vercel's Next.js, but the post lacks technical details, PoC, patch information, or evidence of active exploitation.

    0000078
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27980 Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization … https://www.cve.org/CVERecord?id=CVE-2026-27980

    Post summary

    The post references CVE‑2026‑27980, points to a CVE record, and mentions affected Next.js versions, but provides no evidence of PoC, exploit code, active attacks, or remediation.

    00000112
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more