Known vulnerabilities in Next.js 16.3.1

Vendor: vercel
Software: Next.js
Version: 16.3.1
Software CPE: cpe:2.3:a:vercel:nextjs:*:*:*:*:*:*:*:*
Total vulnerabilities: 3
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Next.js version 16.3.1 Next.js 16.3.1 is affected by 3 vulnerabilities: 3 high Critical High Medium Low

Vulnerabilities (3)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU151855 - Improper input validation
CVE-2026-94545
CWE-20 High
No
No
16.3.6 23.09.2026 SB2026092349
#VU145734 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-75604
CWE-22 High
Public exploit available
Exploited
15.5.24, 16.3.3 26.08.2026 SB2026082633
#VU145733 - Memory corruption
CWE-119 High
No
No
15.5.24, 16.3.3 26.08.2026 SB2026082633