Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks
ID: 78a37322-6749-5c40-9d83-f1b07cb972db
STIX ID: report--78a37322-6749-5c40-9d83-f1b07cb972db
Feed Name: cybersecurityNews.com
Threat Score
Vercel disclosed and patched nine vulnerabilities in Next.js affecting versions as early as 12.0.0 through 16.2.11, including high-severity SSRF in rewrites and Server Actions, a middleware/proxy bypass that can skip authorization, DoS via Server Actions and image processing, plus several moderate cache and payload issues; organizations are advised to upgrade to 15.5.21 or 16.2.11 and review rewrites, custom servers, Turbopack middleware, and Cache Components.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
