Next.js Framework 15.x < 15.6.0-canary.61 / 16.x < 16.1.5 PPR Resume Endpoint DoS (GHSA-5f7q-jpqc-wp7h)

medium Nessus Plugin ID 297815

Synopsis

The Next.js Framework on the remote host is affected by a denial of service vulnerability.

Description

The Next.js Framework on the remote host is affected by a denial of service vulnerability:

- A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the Next-Resume: 1 header and processes attacker-controlled postponed state data. Two closely related vulnerabilities allow an attacker to crash the server process through memory exhaustion: unbounded request body buffering where the server buffers the entire POST request body into memory using Buffer.concat() without enforcing any size limit, and unbounded decompression (zipbomb) where the resume data cache is decompressed using inflateSync() without limiting the decompressed output size. Both attack vectors result in a fatal V8 out-of-memory error causing the Node.js process to terminate. (CVE-2025-59472)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Next.js Framework version 15.6.0-canary.61, 16.1.5 or later.

See Also

http://www.nessus.org/u?3f0675bd

Plugin Details

Severity: Medium

ID: 297815

File Name: nextjs_framework_CVE-2025-59472.nasl

Version: 1.2

Type: local

Agent: windows, macosx, unix

Family: Misc.

Published: 2/4/2026

Updated: 2/5/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2025-59472

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:vercel:next.js

Required KB Items: Host/nodejs/modules/enumerated

Exploit Ease: No known exploits are available

Patch Publication Date: 1/26/2026

Vulnerability Publication Date: 1/26/2026

Reference Information

CVE: CVE-2025-59472

IAVA: 2026-A-0090