Next.js shipped security updates across recent releases: 15.5.21 and 16.2.11, patching 15 total vulnerabilities (4 high, 5 medium). The hot zones include App Router, Server Actions, and Turbopack—key parts of the modern Next.js stack. What can go wrong if your app is still on an affected version? Security researchers warn attackers may craft requests that keep server resources tied up, leading to denial-of-service. In other cases, they could bypass existing protections by abusing implementation details—or trick the server into making outbound connections to attacker-chosen hosts. High-severity issues include: • CVE-2026-64641: App Router + Server Actions apps could be forced into heavy CPU/compute loops, blocking follow-up requests. • CVE-2026-64642: Turbopack-built i18n configurations may let attackers skip security checks that depend on certain layers. • CVE-2026-64645 and CVE-2026-64649: routing/redirect and Server Actions scenarios that can enable SSRF-like behavior or malicious host targeting. Fixes are in 16.3.0-canary.92 and 16.3.0-preview.7, on track for 16.3.0 stable. Upgrade ASAP. #Nextjs #AppRouter #ServerActions #Turbopack #WebSecurity #CVE
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论