Multiple Critical Vulnerabilities Patched in Next.js and React Server Components
ID: 1363fe06-b6bb-56da-9e6f-838b2fbffe45
STIX ID: report--1363fe06-b6bb-56da-9e6f-838b2fbffe45
Feed Name: Cyber Press
Vercel released urgent security updates for Next.js (patches in 15.5.16 and 16.2.5) that fix multiple high-severity issues: middleware authentication bypasses allowing access to protected content, two DoS vulnerabilities that can exhaust CPU or deadlock request handling, and a critical SSRF that lets unauthenticated actors proxy requests from self-hosted Node.js servers to internal or external targets. The flaws affect App Router, Pages Router (with i18n), Cache Components used for Partial Prerendering, and self-hosted deployments; Vercel recommends immediate upgrades, blocking WebSocket upgrade headers at the edge, and enforcing authorization in page-level code as interim mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
