Excessive Iteration in Next.js - CVE-2026-64641
Published: July 22, 2026
Next.js
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to excessive iteration in App Router server actions handling when processing crafted requests. A remote attacker can send crafted requests to cause a denial of service.
Only applications using App Router with at least one Server Action are vulnerable.