CVE-2026-64649

Red Hat Security Advisory: Streams for Apache Kafka 3.2.1 release and security update

Beschreibung

Next.js ist ein React-Framework zum Erstellen von Full-Stack-Webanwendungen. In den Versionen 14.1.1 bis 15.5.20 und 16.0.0 bis 16.2.10 kann bei der Weiterleitung oder Umleitung einer Anfrage durch eine Server-Aktion ein Angreifer verursachen, dass der Server die ausgehende Anfrage an einen bösartigen Host sendet (Server-Side Request Forgery). Dies erfordert, dass der Angreifer die Host-bezogenen Header kontrolliert. In einigen Konfigurationen ist es auch möglich, interne Werte zu erhalten, die die Autorisierung von Middleware/Proxy schwächen. Anwendungen, die Server-Aktionen verwenden, sind betroffen, wenn der eingehende Host-Header nicht auf einen vertrauenswürdigen Wert festgelegt wird. Dies tritt typischerweise bei benutzerdefinierten Servern oder Bereitstellungen ohne Proxy auf, der den Host fixiert. Managed Hosting fixiert den Host upstream und ist nicht betroffen; next start und standalone Ausgabe tun dies ab Version 14.2. Dieses Problem wurde in den Versionen 15.5.21 und 16.2.11 behoben.

Metriken

Severity
high
kein öffentlicher PoC bekannt
8.3
Quelle: nvd-v4
56.7 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.9 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-12 19:35 UTC
CWE-918

Weakness-Klassen (CWE)

  • CWE-918Base

    Server-Side Request Forgery (SSRF)

    The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-07-29 14:38 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
    • CPE Configuration: OR *cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* versions from (including) 14.1.1 up to (excluding) 15.5.21 *cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* versions from (including) 16.0.0 up to (excluding) 16.2.11
    • Reference Type: GitHub, Inc.: https://github.com/vercel/next.js/commit/b51206321854193208c0805ba42acc49287f942b Types: Patch
    • Reference Type: GitHub, Inc.: https://github.com/vercel/next.js/commit/e3e5666ccead3a15162793d697af5e48b7cc0498 Types: Patch
  2. CVE Modified2026-07-28 15:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-64649","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-07-27 20:16 UTC· security-advisories@github.com
    • Affected: next.js
    • Description: Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization. Applications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs on custom servers, or on deployments not behind a proxy that pins the host. Managed hosting pins the host upstream and is not affected; next start and standalone output do the same from version 14.2 onward. This issue has been fixed in versions 15.5.21 and 16.2.11.
    • CVSS V4.0: AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CWE: CWE-918

Betroffene Betriebssysteme

  • linux

    ubuntu / nettynoble

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    kafka2.8.0 – 3.9.2

  • apache

    kafka4.0.0 – 4.0.2

  • apache

    kafka4.1.0 – 4.1.2

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • bitnami

    golang1.26.0-0

  • eclipse

    vert.x4.0.0 – 4.5.29

  • eclipse

    vert.x5.0.0 – 5.1.4

  • go

    stdlib1.26.0-0

  • golang

    go1.26.0 – 1.26.2

  • golang

    go1.26.0 – 1.26.3

  • golang

    go1.25.10

  • golang

    go1.25.9

  • golang

    net0.55.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

Quellen & Referenzen

Verknüpfte CVEs

33 weitere CVEs anzeigen
IDCVE-2026-64649