highVulnerability

CVE-2026-64641

## Impact Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. ## Workarounds No workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.

Properties

ghsa_id
GHSA-m99w-x7hq-7vfj
summary
Next.js: Denial of Service in App Router using Server Actions
severity
high
epss_score
0.01055
cve_id
CVE-2026-64641
is_ghsa_only
false
ghsa_published
2026-07-22T22:59:01Z
source_url
https://github.com/advisories/GHSA-m99w-x7hq-7vfj
epss_percentile
0.61691
ghsa_updated
2026-07-22T22:59:03Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/next

AFFECTS (1)

[Software]npm/next

HAS_WEAKNESS (1)

[Weakness]Excessive Iteration

Explore deeper with Ninja Signal's threat intelligence graph