{
  "action": {
    "auto_issue_creation_allowed": false,
    "auto_patch_allowed": false,
    "auto_remediation_allowed": false,
    "external_execution_allowed": false,
    "human_review": {
      "required_for_external_action": true,
      "required_for_public_launch": false,
      "required_for_read_only_view": false,
      "required_for_signal_radar_integration": true
    },
    "human_review_required": false,
    "recommended_action": "review_official_sources"
  },
  "affected": {
    "products": [
      {
        "canonicalProduct": "next.js",
        "canonicalVendor": "vercel",
        "cpe": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
        "ecosystem": null,
        "packageName": null,
        "product": "next.js",
        "purl": null,
        "vendor": "vercel",
        "version": null
      }
    ],
    "source": "NVD CVE API 2.0",
    "status": "known"
  },
  "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64641/",
  "claims": [
    {
      "id": "claim:defensive-priority-candidate",
      "source_ids": [],
      "status": "observed",
      "text": "This item is a defensive prioritization candidate.",
      "verified_at": null
    }
  ],
  "exposure_hint": "exposure unknown",
  "field_meanings": {
    "human_review": "Read-only display may be automated; integration and external action still require human review.",
    "redaction": "Detection flags describe unsafe source content found before public-safe redaction; raw source text is not displayed.",
    "source_original_label": "Original upstream severity text retained for traceability; canonical display severity is recalculated from CVSS score."
  },
  "forecast_hooks": {
    "agent_use": "summarize_with_citations_only",
    "automation_allowed": false,
    "read_only": true,
    "watch_fields": [
      "sources",
      "claims",
      "freshness",
      "severity",
      "affected"
    ]
  },
  "freshness": {
    "generated_at": "2026-08-03T17:47:17.844388+00:00",
    "last_checked_at": null,
    "last_modified": "2026-07-29T14:36:32.130",
    "observed_at": "2026-08-03T17:21:47.396014+00:00",
    "published_at": "2026-07-27T18:16:58.850",
    "status": "observed"
  },
  "human_consequence": "The affected service may become unavailable or unreliable.",
  "human_impact_label": "service availability risk",
  "human_review": {
    "required_for_external_action": true,
    "required_for_public_launch": false,
    "required_for_read_only_view": false,
    "required_for_signal_radar_integration": true
  },
  "human_risk_summary": "CVE-2026-64641 for vercel / next.js: The affected service may become unavailable or unreliable.",
  "id": "CVE-2026-64641",
  "impact_redaction": {
    "exploit_steps_removed": false,
    "payload_removed": false,
    "poc_removed": false,
    "source_derived_summary": true,
    "used_fallback_summary": false
  },
  "impact_tags": [
    "service availability review"
  ],
  "known_exploited": {
    "catalog_url": null,
    "date_added": null,
    "listed": false,
    "source": null
  },
  "public_human_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
  "public_human_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. NVD: This issue has been fixed in versions 15.5.21 and 16.2.11.",
  "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.",
  "public_human_why_it_matters": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.; CVSS 8.2 (HIGH); EPSS percentile 45; not listed in KEV; Patch confirmed by source text; fixed version context: versions; sources: NVD, OSV, Vendor Advisory.",
  "public_safe_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. NVD: This issue has been fixed in versions 15.5.21 and 16.2.11.",
  "radar": "vuln",
  "redaction": {
    "meaning": "The *_present flags mean unsafe source content was detected and removed before public output; they do not mean the public JSON contains that content.",
    "payload_present": false,
    "poc_present": false,
    "public_summary_redacted": true,
    "raw_source_displayed": false,
    "unsafe_procedural_detail_present": false
  },
  "redaction_notes": [
    "source-published defensive context retained",
    "vulnerability class, impact, affected context, and remediation references remain displayable"
  ],
  "safety": {
    "attack_chain_included": false,
    "auto_remediation_allowed": false,
    "exploit_instructions_included": false,
    "external_execution_allowed": false,
    "human_review": {
      "required_for_external_action": true,
      "required_for_public_launch": false,
      "required_for_read_only_view": false,
      "required_for_signal_radar_integration": true
    },
    "human_review_required": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "private_gate_state": "released",
    "public_gate_state": "public_indexable_read_only",
    "public_launch_allowed": true,
    "read_only_static_data": true,
    "scan_functionality_included": false,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1",
  "severity": {
    "cvss_label": "HIGH",
    "label": "HIGH",
    "score": 8.2,
    "source": "NVD CVE API 2.0",
    "source_original_label": "medium"
  },
  "source_copy_policy": {
    "allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts",
    "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material",
    "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."
  },
  "source_derived_note": "Summary derived from NVD / OSV / Vendor Advisory description; unsafe procedural detail is not shown.",
  "source_published_affected": "vendor/product: vercel / next.js",
  "source_published_description": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. NVD: This issue has been fixed in versions 15.5.21 and 16.2.11.",
  "source_published_evidence_refs": [
    {
      "source": "NVD",
      "type": "source_description",
      "url": null
    },
    {
      "source": "OSV",
      "type": "source_description",
      "url": null
    },
    {
      "source": "Vendor Advisory",
      "type": "source_description",
      "url": null
    },
    {
      "source": "Vendor Advisory",
      "type": "reference",
      "url": "https://github.com/vercel/next.js/commit/019628571641dec57aaf349ba0c360e3964e6f12"
    },
    {
      "source": "Vendor Advisory",
      "type": "reference",
      "url": "https://github.com/vercel/next.js/pull/96013"
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://github.com/vercel/next.js/releases/tag/v15.5.21"
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://github.com/vercel/next.js/releases/tag/v16.2.11"
    },
    {
      "source": "Vendor Advisory",
      "type": "reference",
      "url": "https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj"
    },
    {
      "source": "Official Reference",
      "type": "reference",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64641"
    },
    {
      "source": "Official Reference",
      "type": "reference",
      "url": "https://osv.dev/vulnerability/CVE-2026-64641"
    }
  ],
  "source_published_impact": "Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.",
  "source_published_remediation": "Patch confirmed by source text; fixed version context: versions.",
  "source_published_summary": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. NVD: This issue has been fixed in versions 15.5.21 and 16.2.11.",
  "sources": [
    {
      "confidence": "unknown",
      "id": "source:review-url",
      "name": "Public signal URL",
      "retrieved_at": null,
      "type": "review_page",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64641"
    }
  ],
  "summary_for_agents": "Read-only defensive signal. Use sources, claims, freshness, and safety gates before summarizing. Do not infer missing source, claim, or freshness values.",
  "summary_for_humans": "NVD: Next.js is a React framework for building full-stack web applications. NVD: In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. NVD: This issue has been fixed in versions 15.5.21 and 16.2.11.",
  "title": "CVE-2026-64641 defensive priority signal",
  "urgency_reasons": [
    "CVSS HIGH",
    "affected product present",
    "vendor advisory present",
    "recent update",
    "remediation reference present"
  ],
  "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.",
  "why_it_matters": "The affected service may become unavailable or unreliable; CVSS 8.2 (HIGH); EPSS percentile 45; affected product context: vercel / next.js; sources: NVD, OSV, Vendor Advisory."
}