logo

Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks

ID: 78a37322-6749-5c40-9d83-f1b07cb972db

STIX ID: report--78a37322-6749-5c40-9d83-f1b07cb972db

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

Author: Guru Baran

...
...

Vercel disclosed and patched nine vulnerabilities in Next.js affecting versions as early as 12.0.0 through 16.2.11, including high-severity SSRF in rewrites and Server Actions, a middleware/proxy bypass that can skip authorization, DoS via Server Actions and image processing, plus several moderate cache and payload issues; organizations are advised to upgrade to 15.5.21 or 16.2.11 and review rewrites, custom servers, Turbopack middleware, and Cache Components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.