A vulnerability was found in Vercel Next.js up to 15.5.20/16.2.10. It has been classified as problematic. Affected by this issue is some unknown functionality of the component App Router. The manipulation leads to uncontrolled memory allocation.

This vulnerability is traded as CVE-2026-64646. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is recommended.