CVE-2026-27978: Next.js: null origin can bypass Server Actions CSRF checks

Published Mar 17, 2026
·
Updated

Summary origin: null was treated as a "missing" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests.

Impact An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing actions with victim credentials (CSRF).

Patches Fixed by treating 'null' as an explicit origin value and enforcing host/origin checks unless 'null' is explicitly allowlisted in experimental.serverActions.allowedOrigins.

Workarounds If upgrade is not immediately possible: - Add CSRF tokens for sensitive Server Actions. - Prefer SameSite=Strict on sensitive auth cookies. - Do not allow 'null' in serverActions.allowedOrigins unless intentionally required and additionally protected.

Other sources

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, origin: null was treated as a "missing" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing actions with victim credentials (CSRF). This is fixed in version 16.1.7 by treating 'null' as an explicit origin value and enforcing host/origin checks unless 'null' is explicitly allowlisted in experimental.serverActions.allowedOrigins. If upgrading is not immediately possible, add CSRF tokens for sensitive Server Actions, prefer SameSite=Strict on sensitive auth cookies, and/or do not allow 'null' in serverActions.allowedOrigins unless intentionally required and additionally protected.

NVD

Affected Software

2 affected componentsFixes available
npm/next>=16.0.1<16.1.7
16.1.7
Vercel Next.js Node.js>=16.0.1<16.1.7

Event History

Mar 17, 2026
Advisory Published
via GitHub·03:30 PM
Data Sourced
via GitHub·03:30 PM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·11:59 PM
Data Sourced
via MITRE·11:59 PM
DescriptionWeakness
Mar 18, 2026
Data Sourced
via NVD·12:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-27978?

CVE-2026-27978 is considered a critical vulnerability due to its ability to bypass origin verification during Server Action CSRF validation.

2

How do I fix CVE-2026-27978?

To fix CVE-2026-27978, upgrade to version 16.1.7 or later of the next.js package.

3

What types of software are affected by CVE-2026-27978?

CVE-2026-27978 affects the next.js package versions from 16.0.1 to 16.1.6.

4

What impact does CVE-2026-27978 have on web applications?

CVE-2026-27978 allows attackers to induce cross-origin requests from opaque contexts, potentially leading to unauthorized actions in web applications.

5

Can I continue using next.js while CVE-2026-27978 exists?

It is highly recommended to mitigate the risks by upgrading or applying security patches to avoid exploitation of CVE-2026-27978.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203