highVulnerability
CVE-2026-64641
## Impact Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. ## Workarounds No workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.
Properties
- ghsa_id
- GHSA-m99w-x7hq-7vfj
- summary
- Next.js: Denial of Service in App Router using Server Actions
- severity
- high
- epss_score
- 0.01055
- cve_id
- CVE-2026-64641
- is_ghsa_only
- false
- ghsa_published
- 2026-07-22T22:59:01Z
- source_url
- https://github.com/advisories/GHSA-m99w-x7hq-7vfj
- epss_percentile
- 0.61691
- ghsa_updated
- 2026-07-22T22:59:03Z
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]npm/next
AFFECTS (1)
→[Software]npm/next
HAS_WEAKNESS (1)
→[Weakness]Excessive Iteration
Explore deeper with Ninja Signal's threat intelligence graph