Vulnerability record · CVE-2021-43803 · published 10 December 2021
CVE-2021-43803: Next.js malformed URL input validation flaw causes server crash
Vercel · Next.Js
Next.js versions prior to 12.0.5 or 11.1.3 fail to properly validate invalid or malformed URLs, allowing a crafted request to crash the server. The flaw affects deployments running Next.js above 11.1.0 and below 12.0.5 on Node.js above 15.0.0 using next start or a custom server; Vercel-hosted and similar filtered environments are not affected.
Description
Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to be affected by this issue, the deployment must use Next.js versions above 11.1.0 and below 12.0.5, Node.js above 15.0.0, and next start or a custom server. Deployments on Vercel are not affected, along with similar environments where invalid requests are filtered before reaching Next.js. Versions 12.0.5 and 11.1.3 contain patches for this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 with network-reachable, unauthenticated availability impact and a high EPSS percentile warrant prompt patching, though there is no KEV listing or confirmed in-the-wild exploitation.
What it is
Next.js versions prior to 12.0.5 or 11.1.3 fail to properly validate invalid or malformed URLs, allowing a crafted request to crash the server. The flaw affects deployments running Next.js above 11.1.0 and below 12.0.5 on Node.js above 15.0.0 using next start or a custom server; Vercel-hosted and similar filtered environments are not affected.
Impact
An unauthenticated attacker can cause a denial of service by crashing the Next.js server process, disrupting availability of the hosted application. There is no stated confidentiality or integrity impact.
Attack surface
Reachable over the network by sending a malformed URL to the affected Next.js server; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Only deployments using next start or a custom server on the specified version and Node.js ranges are exposed.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at roughly 0.448 (98.7th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade Next.js to 12.0.5 or 11.1.3 (or later) as the primary fix.
- If immediate upgrade is not possible, place a reverse proxy or WAF in front of the app to reject malformed or invalid URL requests before they reach Next.js.
- Confirm the deployment uses next start or a custom server and runs Node.js above 15.0.0, since those conditions are required for exposure.
- For Vercel-hosted or similarly filtered environments, verify that invalid requests are filtered before reaching Next.js.
- Monitor Node.js process restarts and crash logs after applying changes to confirm the issue is resolved.
Detection
- Monitor application and Node.js process crash logs for unexpected exits correlated with malformed URL requests.
- Inspect reverse proxy or load balancer access logs for requests containing malformed or invalid URL patterns.
- Track server availability and restart frequency to detect denial-of-service patterns.
- Alert on repeated 5xx responses or connection resets originating from single or distributed sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/vercel/next.js/commit/6d98b4fb4315dec1badecf0e9bdc212a4272b264 | PatchThird Party Advisory |
| https://github.com/vercel/next.js/pull/32080 | PatchThird Party Advisory |
| https://github.com/vercel/next.js/releases/tag/v11.1.3 | Release NotesThird Party Advisory |
| https://github.com/vercel/next.js/releases/v12.0.5 | Release NotesThird Party Advisory |
| https://github.com/vercel/next.js/security/advisories/GHSA-25mp-g6fv-mqxx | PatchThird Party Advisory |
| https://github.com/vercel/next.js/commit/6d98b4fb4315dec1badecf0e9bdc212a4272b264 | PatchThird Party Advisory |
| https://github.com/vercel/next.js/pull/32080 | PatchThird Party Advisory |
| https://github.com/vercel/next.js/releases/tag/v11.1.3 | Release NotesThird Party Advisory |
| https://github.com/vercel/next.js/releases/v12.0.5 | Release NotesThird Party Advisory |
| https://github.com/vercel/next.js/security/advisories/GHSA-25mp-g6fv-mqxx | PatchThird Party Advisory |
Track CVE-2021-43803 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-43803), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.