Zack Tanner
7 exploits
Active since Jul 2025
Next.js: Cache poisoning in React Server Component responses
CVSS 5.4
Next.js 16.0.1-16.1.6 - Postponed Resume Buffering Denial of Service
CVSS 7.5
Next.js: HTTP request smuggling in rewrites
CVSS 6.5
Next.js: null origin can bypass dev HMR websocket CSRF checks
CVSS 5.4
Next.js: null origin can bypass Server Actions CSRF checks
CVSS 4.3
Next.js 15.0.4-15.1.8 - Denial of Service via HTTP 204 Response Cache Poisoning
CVSS 7.5
Next.js < 14.2.32 - Server-Side Request Forgery via next() Function
CVSS 6.5