Next.js moves to scheduled security releases
ID: 853c7f5f-42cf-5d65-af17-31bb9cb174c7
STIX ID: report--853c7f5f-42cf-5d65-af17-31bb9cb174c7
Feed Name: Socket Blog
Vercel is instituting a monthly, pre-announced security release program for Next.js after a series of high-severity issues — notably React2Shell (CVE-2025-55182), a CVSS 10.0 pre-auth RCE that was actively exploited at scale, and a CVSS 9.1 authorization bypass — exposed hundreds of thousands of instances and attracted both opportunistic criminals and state-affiliated actors; the scheduled cadence aims to improve patch planning, partner mitigation (WAF rules, hosting protections), and coordinated disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
