GHSA-h25m-26qc-wcjf
HighAdvisory
Published 28 Jan 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- —
- probability of exploitation
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 52
- of 17,781 indexed, latest versions
- Container images
- 53
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
Carried by container images the latest versions of 52 of 17,781 indexed charts deploy, on 53 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nextnpm | 13.0.7, 13.2.4, 13.4.12, 13.5.2+32 more | 15.0.8, 15.2.9, 15.3.9, 15.4.11+3 more | 53 |
- OSV records
- GHSA-h25m-26qc-wcjf
Charts affected
52 by stars
Container images carrying it
53 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.