
Summary We have shipped a coordinated security release for Next.js addressing 13 advisories across denial of service, middleware and proxy bypass, server-side request forgery, cache poisoning, and cross-site scripting. One advisory addresses an upstream React Server Components vulnerability tracked as . CVE-2026-23870 Patched versions are available for both React and Next.js, and all should upgrade immediately.affected users The release addresses the following advisories: Affects applications that rely on or for authorization.middleware.jsproxy.js Affects applications using Server Functions, Partial Prerendering with Cache Components, or the Image Optimization API. Affects applications that handle WebSocket upgrade requests. Affects applications with caching layers in front of React Server Component responses. Affects applications using CSP nonces in App Router, or scripts that consume untrusted input.beforeInteractive These vulnerabilities are addressed by the patched releases of React and Next.js. Patching is the only complete mitigation, and all should upgrade immediately. affected users Vercel has not deployed new WAF rules for this release; these advisories cannot be reliably blocked at the WAF layer. Frameworks and bundlers using packages should install the latest versions provided by their respective maintainers.react-server-dom-* Read more Recommended actions Middleware and proxy bypass Denial of service Server-side request forgery Cache poisoning Cross-site scripting Impact Resolution Affected versions Fixed in References : HighAuth bypass via App Router segment-prefetch URL : HighApp Router segment-prefetch bypass, incomplete fix follow-up : HighPages Router i18n default-locale path bypasses proxy authorization : HighBypass via dynamic route parameter injection : LowMiddleware redirects can be cache-poisoned : (tracked upstream as )HighDoS in React Server ComponentsCVE-2026-23870 : HighDoS via connection exhaustion in applications using Cache Components : ModerateDoS via the Image Optimization API : HighSSRF in applications using WebSocket upgrades : ModerateCache poisoning in React Server Component responses : LowCache poisoning via collisions in RSC cache-busting : ModerateXSS in App Router applications using CSP nonces : ModerateXSS in beforeInteractive scripts with untrusted input : , Next.js15.5.1816.2.6 : , , for the , and packagesReact19.0.619.1.719.2.6react-server-dom-parcelreact-server-dom-webpackreact-server-dom-turbopack Upstream React advisory (CVE-2026-23870) Package Affected Upgrade to , Next.js 13.x14.x all versions or 15.5.1816.2.6 Next.js 15.x <=15.5.17 15.5.18 Next.js 16.x <=16.2.5 16.2.6 react-server-dom-*19.0.x <=19.0.5 19.0.6 react-server-dom-*19.1.x <=19.1.6 19.1.7 react-server-dom-*19.2.x <=19.2.5 19.2.6
No discussion yet. Be the first to share your thoughts!