Skip to content

Next.js: null origin can bypass dev HMR websocket CSRF checks

Low severity GitHub Reviewed Published Mar 16, 2026 in vercel/next.js • Updated Mar 25, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts