← Vulnerability feed

Vulnerability record · CVE-2021-43803 · published 10 December 2021

CVE-2021-43803: Next.js malformed URL input validation flaw causes server crash

Vercel · Next.Js

Next.js versions prior to 12.0.5 or 11.1.3 fail to properly validate invalid or malformed URLs, allowing a crafted request to crash the server. The flaw affects deployments running Next.js above 11.1.0 and below 12.0.5 on Node.js above 15.0.0 using next start or a custom server; Vercel-hosted and similar filtered environments are not affected.

7.5 CVSS 3.1 High EPSS 45% · top 1.3% CWE-20 · Improper input validation
7.5CVSS 3.1 base score, v2 4.3
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to be affected by this issue, the deployment must use Next.js versions above 11.1.0 and below 12.0.5, Node.js above 15.0.0, and next start or a custom server. Deployments on Vercel are not affected, along with similar environments where invalid requests are filtered before reaching Next.js. Versions 12.0.5 and 11.1.3 contain patches for this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 7.5 with network-reachable, unauthenticated availability impact and a high EPSS percentile warrant prompt patching, though there is no KEV listing or confirmed in-the-wild exploitation.

What it is

Next.js versions prior to 12.0.5 or 11.1.3 fail to properly validate invalid or malformed URLs, allowing a crafted request to crash the server. The flaw affects deployments running Next.js above 11.1.0 and below 12.0.5 on Node.js above 15.0.0 using next start or a custom server; Vercel-hosted and similar filtered environments are not affected.

Impact

An unauthenticated attacker can cause a denial of service by crashing the Next.js server process, disrupting availability of the hosted application. There is no stated confidentiality or integrity impact.

Attack surface

Reachable over the network by sending a malformed URL to the affected Next.js server; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Only deployments using next start or a custom server on the specified version and Node.js ranges are exposed.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at roughly 0.448 (98.7th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Upgrade Next.js to 12.0.5 or 11.1.3 (or later) as the primary fix.
  • If immediate upgrade is not possible, place a reverse proxy or WAF in front of the app to reject malformed or invalid URL requests before they reach Next.js.
  • Confirm the deployment uses next start or a custom server and runs Node.js above 15.0.0, since those conditions are required for exposure.
  • For Vercel-hosted or similarly filtered environments, verify that invalid requests are filtered before reaching Next.js.
  • Monitor Node.js process restarts and crash logs after applying changes to confirm the issue is resolved.

Detection

  • Monitor application and Node.js process crash logs for unexpected exits correlated with malformed URL requests.
  • Inspect reverse proxy or load balancer access logs for requests containing malformed or invalid URL patterns.
  • Track server availability and restart frequency to detect denial-of-service patterns.
  • Alert on repeated 5xx responses or connection resets originating from single or distributed sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-43803 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-55182React Server Components pre-auth deserialization RCEReact Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) u…KEVEPSS 100%analysed9.1CVE-2025-29927Next.js middleware authorization bypass via x-middleware-subrequest headerNext.js versions from 1.11.4 up to (but not including) 12.3.5, 13.5.9, 14.2.25, and 15.2.3 allow authorization checks performed in middleware to be b…EPSS 99%analysed8.6CVE-2026-44578Vercel next.js server-side request forgery (ssrf) vulnerabilityNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the …EPSS 1.9%8.3CVE-2026-64649Vercel next.js server-side request forgery (ssrf) vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server A…EPSS 0.46%8.3CVE-2026-64642Vercel next.js improper authorization vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applica…EPSS 0.64%8.3CVE-2026-64645Vercel next.js open redirect vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or…EPSS 0.41%8.2CVE-2026-64641Vercel next.js vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted request…EPSS 0.86%8.2CVE-2025-57822Vercel next.js server-side request forgery (ssrf) vulnerabilityNext.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2021-43803), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.