Buffering Vulnerability in Next.js Framework by Vercel
CVE-2026-27979
What is CVE-2026-27979?
A vulnerability in Vercel's Next.js framework allows attackers to exploit unbounded request body buffering. When specific headers such as 'next-resume: 1' were sent, systems using the App Router with Partial Prerendering could experience excessive memory consumption, potentially leading to denial of service. This condition arises when oversized POST requests are improperly handled, particularly in non-minimal mode deployments. Mitigation is achieved in version 16.1.7, where limits on buffered request sizes are consistently enforced. Users unable to upgrade should consider blocking requests with the 'next-resume' header from untrusted clients.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
next.js >= 16.0.1, < 16.1.7