Vercel has disclosed and patched nine security vulnerabilities in Next.js, the widely used React framework, addressing flaws that could enable server-side request forgery (SSRF), middleware authentication bypass, denial-of-service (DoS) attacks, and sensitive data exposure. All nine advisories were published two days ago by security researcher KarimPwnz and are now fixed in Next.js versions 15.5.21 and 16.2.11. Earlier, Next.js announced it would launch a monthly security release program. This update will address nine vulnerabilities across supported versions of the framework. Next.js Patches Multiple Vulnerabilities The most critical issue, tracked as CVE-2026-64645 (GHSA-p9j2-gv94-2wf4), is a high-severity SSRF vulnerability...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!