chore(deps): update dependency next to v15.5.15 [security] - #821
Open
renovate[bot] wants to merge 2 commits into
Open
chore(deps): update dependency next to v15.5.15 [security]#821renovate[bot] wants to merge 2 commits into
renovate[bot] wants to merge 2 commits into
Conversation
canonical-iam
approved these changes
Dec 4, 2025
canonical-iam
enabled auto-merge
December 4, 2025 11:22
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
December 4, 2025 16:50
85b9a75 to
61781d6
Compare
canonical-iam
approved these changes
Dec 4, 2025
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
December 5, 2025 09:13
61781d6 to
c22168e
Compare
canonical-iam
approved these changes
Dec 5, 2025
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
December 5, 2025 09:21
c22168e to
43d8c04
Compare
canonical-iam
approved these changes
Dec 5, 2025
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
December 8, 2025 21:35
43d8c04 to
93920cb
Compare
canonical-iam
previously approved these changes
Dec 8, 2025
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
December 13, 2025 12:03
93920cb to
95234d6
Compare
canonical-iam
approved these changes
Dec 13, 2025
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
January 7, 2026 15:25
95234d6 to
64a5389
Compare
canonical-iam
approved these changes
Jan 7, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
January 8, 2026 18:22
64a5389 to
9129d59
Compare
canonical-iam
approved these changes
Jan 8, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
January 16, 2026 14:04
9129d59 to
f37eba8
Compare
canonical-iam
approved these changes
Jan 16, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
January 19, 2026 12:29
f37eba8 to
30caf6c
Compare
canonical-iam
approved these changes
Jan 19, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
January 20, 2026 18:23
30caf6c to
ce2af0c
Compare
canonical-iam
previously approved these changes
Jan 20, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
January 22, 2026 08:48
ce2af0c to
48621c1
Compare
canonical-iam
approved these changes
Jan 22, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
January 26, 2026 12:36
48621c1 to
dcdc43c
Compare
canonical-iam
approved these changes
Mar 31, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
April 9, 2026 17:58
ecda3e1 to
44bd309
Compare
canonical-iam
previously approved these changes
Apr 9, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
April 17, 2026 16:19
44bd309 to
ae075f9
Compare
canonical-iam
approved these changes
Apr 17, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
April 24, 2026 08:53
ae075f9 to
ca53322
Compare
canonical-iam
approved these changes
Apr 24, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
April 27, 2026 08:38
ca53322 to
eac253d
Compare
canonical-iam
approved these changes
Apr 27, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
April 27, 2026 09:05
eac253d to
dea01a6
Compare
canonical-iam
approved these changes
Apr 27, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
April 30, 2026 15:41
dea01a6 to
b1bd4c2
Compare
canonical-iam
approved these changes
Apr 30, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
April 30, 2026 15:45
b1bd4c2 to
040c2c5
Compare
canonical-iam
approved these changes
Apr 30, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
May 1, 2026 09:16
040c2c5 to
d998ed8
Compare
canonical-iam
approved these changes
May 1, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
May 4, 2026 08:54
d998ed8 to
88bde77
Compare
canonical-iam
approved these changes
May 4, 2026
renovate
Bot
force-pushed
the
renovate/auto-npm-next-vulnerability
branch
from
May 4, 2026 13:39
88bde77 to
ea59391
Compare
canonical-iam
previously approved these changes
May 4, 2026
BarcoMasile
dismissed
canonical-iam’s stale review
May 4, 2026 13:41
The merge-base changed after approval.
Contributor
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
15.5.8→15.5.15Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
GHSA-5j59-xgg2-r9c4
More information
Details
It was discovered that the fix for CVE-2025-55184 in React Server Components was incomplete and did not fully mitigate denial-of-service conditions across all payload types. As a result, certain crafted inputs could still trigger excessive resource consumption.
This vulnerability affects React versions 19.0.2, 19.1.3, and 19.2.2, as well as frameworks that bundle or depend on these versions, including Next.js 13.x, 14.x, 15.x, and 16.x when using the App Router. The issue is tracked upstream as CVE-2025-67779.
A malicious actor can send a specially crafted HTTP request to a Server Function endpoint that, when deserialized, causes the React Server Components runtime to enter an infinite loop. This can lead to sustained CPU consumption and cause the affected server process to become unresponsive, resulting in a denial-of-service condition in unpatched environments.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
GHSA-h25m-26qc-wcjf
More information
Details
A vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as CVE-2026-23864.
A specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage, out-of-memory exceptions, or server crashes. This can result in denial of service in unpatched environments.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
CVE-2025-59471 / GHSA-9g9p-9gw9-jx7f
More information
Details
A DoS vulnerability exists in self-hosted Next.js applications that have
remotePatternsconfigured for the Image Optimizer. The image optimization endpoint (/_next/image) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires thatremotePatternsis configured to allow image optimization from external domains and that the attacker can serve or control a large image on an allowed domain.Strongly consider upgrading to 15.5.10 and 16.1.5 to reduce risk and prevent availability issues in Next applications.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Next.js: HTTP request smuggling in rewrites
CVE-2026-29057 / GHSA-ggv3-7p47-pfv8
More information
Details
Summary
When Next.js rewrites proxy traffic to an external backend, a crafted
DELETE/OPTIONSrequest usingTransfer-Encoding: chunkedcould trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes.Impact
An attacker could smuggle a second request to unintended backend routes (for example, internal/admin endpoints), bypassing assumptions that only the configured rewrite destination/path is reachable. This does not impact applications hosted on providers that handle rewrites at the CDN level, such as Vercel.
Patches
The vulnerability originated in an upstream library vendored by Next.js. It is fixed by updating that dependency’s behavior so
content-length: 0is added only when bothcontent-lengthandtransfer-encodingare absent, andtransfer-encodingis no longer removed in that code path.Workarounds
If upgrade is not immediately possible:
DELETE/OPTIONSrequests on rewritten routes at your edge/proxy.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Next.js: Unbounded next/image disk cache growth can exhaust storage
CVE-2026-27980 / GHSA-3x4c-7xq6-9pq8
More information
Details
Summary
The default Next.js image optimization disk cache (
/_next/image) did not have a configurable upper bound, allowing unbounded cache growth.Impact
An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. Note that this does not impact platforms that have their own image optimization capabilities, such as Vercel.
Patches
Fixed by adding an LRU-backed disk cache with
images.maximumDiskCacheSize, including eviction of least-recently-used entries when the limit is exceeded. SettingmaximumDiskCacheSize: 0disables disk caching.Workarounds
If upgrade is not immediately possible:
.next/cache/images.images.localPatterns,images.remotePatterns, andimages.qualities)Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Next.js has a Denial of Service with Server Components
GHSA-q4gf-8mx6-v5v3
More information
Details
A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as CVE-2026-23869. You can read more about this advisory our this changelog.
A specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of service in unpatched environments.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
vercel/next.js (next)
v15.5.15Compare Source
Please refer the following changelogs for more information about this security release:
https://vercel.com/changelog/summary-of-cve-2026-23869
v15.5.14Compare Source
v15.5.13Compare Source
v15.5.12Compare Source
This is a re-release of v15.5.11 applying the turbopack changes.
v15.5.11Compare Source
Core Changes
Credits
Huge thanks to @timneutkens, @mischnic, @ztanner, and @wyattjoh for helping!
v15.5.10Compare Source
Please refer the following changelogs for more information about this security release:
v15.5.9Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.