Bug 2477193 (CVE-2026-44579) - CVE-2026-44579 next.js: Next.js: Denial of Service via crafted POST requests to server actions
Summary: CVE-2026-44579 next.js: Next.js: Denial of Service via crafted POST requests ...
Keywords:
Status: NEW
Alias: CVE-2026-44579
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2484224 2484226 2484228 2484230 2484239 2484242 2484245
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-13 18:01 UTC by OSIDB Bzimport
Modified: 2026-07-02 00:04 UTC (History)
16 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:34608 0 None None None 2026-07-02 00:04:57 UTC

Description OSIDB Bzimport 2026-05-13 18:01:55 UTC
Next.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are denied service. This vulnerability is fixed in 15.5.16 and 16.2.5.

Comment 2 errata-xmlrpc 2026-07-02 00:04:56 UTC
This issue has been addressed in the following products:

  Streams for Apache Kafka 2.9.4

Via RHSA-2026:34608 https://access.redhat.com/errata/RHSA-2026:34608


Note You need to log in before you can comment on or make changes to this bug.