Buffering Vulnerability in Next.js Framework by Vercel
CVE-2026-27979

6.9MEDIUM

Key Information:

Vendor

Vercel

Status
Vendor
CVE Published:
18 March 2026

What is CVE-2026-27979?

A vulnerability in Vercel's Next.js framework allows attackers to exploit unbounded request body buffering. When specific headers such as 'next-resume: 1' were sent, systems using the App Router with Partial Prerendering could experience excessive memory consumption, potentially leading to denial of service. This condition arises when oversized POST requests are improperly handled, particularly in non-minimal mode deployments. Mitigation is achieved in version 16.1.7, where limits on buffered request sizes are consistently enforced. Users unable to upgrade should consider blocking requests with the 'next-resume' header from untrusted clients.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

next.js >= 16.0.1, < 16.1.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.