Crypto Ticker:
sysadmin from Cyber Security News

Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks

Guru Baran
6 hours ago
5 Views
0 Comments
Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks

Vercel has disclosed and patched nine security vulnerabilities in Next.js, the widely used React framework, addressing flaws that could enable server-side request forgery (SSRF), middleware authentication bypass, denial-of-service (DoS) attacks, and sensitive data exposure. All nine advisories were published two days ago by security researcher KarimPwnz and are now fixed in Next.js versions 15.5.21 and 16.2.11. Earlier, Next.js announced it would launch a monthly security release program. This update will address nine vulnerabilities across supported versions of the framework. Next.js Patches Multiple Vulnerabilities The most critical issue, tracked as CVE-2026-64645 (GHSA-p9j2-gv94-2wf4), is a high-severity SSRF vulnerability...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!