CVE-2026-64649 | Vercel Next.js up to 15.5.20/16.2.10 server-side request forgery
A vulnerability described as critical has been identified in Vercel Next.js up to 15.5.20/16.2.10. This affects an unknown function. The manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2026-64649. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More