Security Update: Multiple vulnerabilities in Next.js
UpdateUnverifiedAdded Sep 24, 2026
The Next.js team has disclosed nine security vulnerabilities, all patched in 15.5.21 and 16.2.11. The issues span server-side request forgery (SSRF), a middleware authorization bypass, denial of service (DoS), and cache/identifier disclosure. Here's what Netlify customers need to know.
Topics: Security, Developer tools
More Netlify releases
Every Netlify release| Date | Release | Type |
|---|---|---|
| Jul 21 | Google Gemini 3.6 Flash and Gemini 3.5 Flash-Lite Now Available in AI Gateway and Agent Runnersunverified Update | Update |
| Jul 20 | Invite Developers and Internal Builders without assigning a projectunverified Update | Update |
| Jul 23 | Security Update: Multiple vulnerabilities in React Routerunverified Update | Update |
| Jul 24 | Claude Opus 5 Now Available in AI Gateway and Agent Runnersunverified Update | Update |
| Jul 27 | Netlify Drop updatesunverified Update | Update |
| Jul 27 | Security Update: Multiple vulnerabilities in Nuxtunverified Update | Update |
| Jul 15 | Set AI usage limits for individual team membersunverified Update | Update |
| Jul 28 | Keep projects private by default with project visibilityunverified Update | Update |
Also shipped on Jul 21, 2026
Netlify in July 2026Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.