logo

Multiple Critical Vulnerabilities Patched in Next.js and React Server Components

ID: 1363fe06-b6bb-56da-9e6f-838b2fbffe45

STIX ID: report--1363fe06-b6bb-56da-9e6f-838b2fbffe45

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-08

Date Updated: 2026-05-22

Author: AnuPriya

...
...

Vercel released urgent security updates for Next.js (patches in 15.5.16 and 16.2.5) that fix multiple high-severity issues: middleware authentication bypasses allowing access to protected content, two DoS vulnerabilities that can exhaust CPU or deadlock request handling, and a critical SSRF that lets unauthenticated actors proxy requests from self-hosted Node.js servers to internal or external targets. The flaws affect App Router, Pages Router (with i18n), Cache Components used for Partial Prerendering, and self-hosted deployments; Vercel recommends immediate upgrades, blocking WebSocket upgrade headers at the edge, and enforcing authorization in page-level code as interim mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.