Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
PRODUCT FAMILYFRAMEWORKMANUAL

Nextjs

Next.js

Next.js is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Lifecycle status

No support or retirement date is shown unless BlackTree can link it to a registered publisher source. A missing date means that a boundary is not publicly stated, has not yet been extracted, or still needs source routing. It does not mean the product is supported indefinitely.

Product overview

Next.js is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

Lifecycle records

No verified lifecycle boundary is currently published for this product family.

Official sources

MANUAL

Next.js official lifecycle source

Registered for manual verification because unattended extraction is unavailable or inappropriate.

Open publisher source

Package vulnerability advisories

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

Fixed: 15.5.21, 16.2.11

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

Fixed: 16.2.11

Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components

Fixed: 15.5.16, 16.2.5

Next.js Vulnerable to Denial of Service with Server Components

Fixed: 15.5.16, 16.2.5

Next.js: Unauthenticated disclosure of internal Server Function endpoints

Fixed: 15.5.21, 16.2.11

Next.js: Cache confusion of response bodies for requests with bodies

Fixed: 15.5.21, 16.2.11

Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

Fixed: 15.5.16, 16.2.5

Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces

Fixed: 15.5.16, 16.2.5