mediumVulnerability

CVE-2026-64646

## Impact Requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime ## Workarounds If you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.

Properties

ghsa_id
GHSA-4c39-4ccg-62r3
severity
medium
summary
Next.js: Unbounded Server Action payload in Edge runtime
epss_score
0.00531
cve_id
CVE-2026-64646
is_ghsa_only
false
ghsa_published
2026-07-22T23:02:43Z
source_url
https://github.com/advisories/GHSA-4c39-4ccg-62r3
epss_percentile
0.42779
ghsa_updated
2026-07-22T23:02:45Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/next

AFFECTS (1)

[Software]npm/next

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

Explore deeper with Ninja Signal's threat intelligence graph