Cross-Site Protection Issue in Next.js Framework by Vercel
CVE-2026-27977
What is CVE-2026-27977?
The Next.js framework, used for building full-stack web applications, had a vulnerability in versions 16.0.1 to 16.1.6 where the development mode could mistakenly allow connections from sensitive contexts through internal websocket endpoints. This security issue arises when the dev server is accessible from attacker-controlled content, leading to potential unauthorized access to the Hot Module Replacement (HMR) websocket channel. The flaw allowed 'Origin: null' to be treated as a valid origin despite configurations in 'allowedDevOrigins'. It is crucial for developers to upgrade to version 16.1.7 or mitigate the exposure of the development server to untrusted networks to avoid exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
next.js >= 16.0.1, < 16.1.7