Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1 advisory

Loading
Next.js is vulnerable to RCE in React flight protocol Critical
GHSA-9qr9-h5gf-34mp was published for next (npm) Dec 3, 2025
lachlan2k Credited to lachlan2k, bytera, larskaare, mswilson, conorfitch, tockn, yusuke-koyoshi, bottarocarlo, and jcburgo bytera bytera
larskaare larskaare mswilson mswilson conorfitch conorfitch tockn tockn yusuke-koyoshi yusuke-koyoshi bottarocarlo bottarocarlo jcburgo jcburgo
ProTip! Advisories are also available from the GraphQL API