Next
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Next product.
RSS Feeds for Next security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Next products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Next Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 1 vulnerability in Next with an average score of 6.9 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 6.90 |
It may take a day or so for new Next vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Next Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-78180 | Aug 24, 2026 |
Alibaba Fusion Next <=1.27.34 Prototype Pollution in ConfigProvider.getContextPropsA security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was closed automatically due to inactivity. |
|
| CVE-1999-0956 | Sep 19, 1997 |
The NeXT NetInfo _writers propertyThe NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service. |
|
| CVE-1999-0046 | Feb 06, 1997 |
Buffer overflow of rlogin program using TERM environmental variable.Buffer overflow of rlogin program using TERM environmental variable. |
|
| CVE-1999-0078 | Apr 18, 1996 |
pcnfsd (aka rpc.pcnfsd)pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. |
|