Wiz Agents & Workflows are here

CVE-2026-27977
ASP.NET Core vulnerability analysis and mitigation

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in next dev, cross-site protection for internal websocket endpoints could treat Origin: null as a bypass case even if allowedDevOrigins is configured, allowing privacy-sensitive/opaque contexts (for example sandboxed documents) to connect unexpectedly. If a dev server is reachable from attacker-controlled content, an attacker may be able to connect to the HMR websocket channel and interact with dev websocket traffic. This affects development mode only. Apps without a configured allowedDevOrigins still allow connections from any origin. The issue is fixed in version 16.1.7 by validating Origin: null through the same cross-site origin-allowance checks used for other origins. If upgrading is not immediately possible, do not expose next dev to untrusted networks and/or block websocket upgrades to /_next/webpack-hmr when Origin is null at the proxy.


SourceNVD

Related ASP.NET Core vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-27980MEDIUM6.9
  • ASP.NET CoreASP.NET Core
  • dotnet-targeting-pack-7.0
NoYesMar 18, 2026
CVE-2026-27979MEDIUM6.9
  • ASP.NET CoreASP.NET Core
  • dotnet-targeting-pack-7.0
NoYesMar 18, 2026
CVE-2026-29057MEDIUM6.3
  • ASP.NET CoreASP.NET Core
  • dotnet-templates-7.0
NoYesMar 18, 2026
CVE-2026-27978MEDIUM5.3
  • ASP.NET CoreASP.NET Core
  • aspnetcore-targeting-pack-7.0
NoYesMar 18, 2026
CVE-2026-27977LOW2.3
  • ASP.NET CoreASP.NET Core
  • dotnet7.0
NoYesMar 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management