Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Aug 31, 2025

This PR contains the following updates:

Package Change Age Confidence
next (source) 16.0.816.0.9 age confidence

GitHub Vulnerability Alerts

GHSA-mwv6-3258-q52c

A vulnerability affects certain React packages for versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, and 19.2.1 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as CVE-2025-55184.

A malicious HTTP request can be crafted and sent to any App Router endpoint that, when deserialized, can cause the server process to hang and consume CPU. This can result in denial of service in unpatched environments.

GHSA-w37m-7fhw-fmv9

A vulnerability affects certain React packages for versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, and 19.2.1 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as CVE-2025-55183.

A malicious HTTP request can be crafted and sent to any App Router endpoint that can return the compiled source code of Server Functions. This could reveal business logic, but would not expose secrets unless they were hardcoded directly into Server Function code.


Release Notes

vercel/next.js (next)

v16.0.9

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch from a6ecf25 to 53c2982 Compare September 25, 2025 17:35
@renovate renovate bot changed the title fix(deps): update dependency next to v15.4.7 [security] chore(deps): update dependency next to v15.4.7 [security] Sep 25, 2025
@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch from 53c2982 to a661d3a Compare October 21, 2025 18:57
@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch from a661d3a to 91e6a65 Compare November 10, 2025 23:14
@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch from 91e6a65 to 0883163 Compare November 18, 2025 23:39
@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch from 0883163 to ff76431 Compare December 3, 2025 15:00
@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch 2 times, most recently from 902eba7 to 7cfccb2 Compare December 11, 2025 13:20
@renovate renovate bot changed the title chore(deps): update dependency next to v15.4.7 [security] chore(deps): update dependency next to v15.4.7 [security] - autoclosed Dec 11, 2025
@renovate renovate bot closed this Dec 11, 2025
@renovate renovate bot deleted the renovate/npm-next-vulnerability branch December 11, 2025 14:09
@renovate renovate bot changed the title chore(deps): update dependency next to v15.4.7 [security] - autoclosed fix(deps): update dependency next to v16.0.9 [security] Dec 12, 2025
@renovate renovate bot reopened this Dec 12, 2025
@renovate renovate bot force-pushed the renovate/npm-next-vulnerability branch from 7cfccb2 to 692b8fa Compare December 12, 2025 05:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant