github.com/nextlevelbuilder/ui-ux-pro-max-skill
Submitted 8/4/2026, 10:25:53 AM · Status: ok
Risk grade
F
100 / 100
Findings
103
0 critical20 high79 medium4 low0 info0 on CISA KEV0ATT&CK
Showing 103 of 103 findings
Findings
- Next.js has a Denial of Service with Server Componentsgrype
- Next.js has a Middleware / Proxy bypass in Pages Router applications using i18ngrypeCVE-2026-44573EPSS 0.6%
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Componentsgrype
- Next.js Vulnerable to Denial of Service with Server Componentsgrype
- Next.js vulnerable to server-side request forgery in applications using WebSocket upgradesgrypeCVE-2026-44578EPSS 38.9%
- Next.js: Denial of Service in App Router using Server ActionsgrypeCVE-2026-64641EPSS 0.5%
- Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostnamegrypeCVE-2026-64645EPSS 1.0%
- Next.js: Server-Side Request Forgery in Server Actions on custom serversgrypeCVE-2026-64649EPSS 0.6%
- PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsgrypeCVE-2026-45623EPSS 0.5%
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosuregrype
- next: Next.js: Denial of Service via crafted requests to App Router with Server ActionsNext.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processi…trivyCVE-2026-64641
- next: Next.js: Server-Side Request Forgery via malicious host redirection in Server ActionsNext.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-S…trivyCVE-2026-64649
- next: Next.js: Server-Side Request Forgery vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostn…trivyCVE-2026-64645
- Next.js has a Denial of Service with Server ComponentsA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react…trivy
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server ComponentsA vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://git…trivy
- Next.js Vulnerable to Denial of Service with Server ComponentsA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react…trivy
- next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-l…trivyCVE-2026-44573
- Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requestsNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker ca…trivyCVE-2026-44578
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…trivy
- postcss: PostCSS: Information disclosure and denial of service via crafted CSS inputPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen…trivyCVE-2026-45623
This report is public.