Skip to content

fix: upgrade Next.js to 15.5.9 to patch CVE-2025-55184 and CVE-2025-55183 - #14

Closed
dcbouius wants to merge 1 commit into
mainfrom
fix-CVE-2025-55184
Closed

fix: upgrade Next.js to 15.5.9 to patch CVE-2025-55184 and CVE-2025-55183#14
dcbouius wants to merge 1 commit into
mainfrom
fix-CVE-2025-55184

Conversation

@dcbouius

Copy link
Copy Markdown
Contributor

Summary

Security Impact

  • CVE-2025-55184 (High) - Denial of Service via malicious HTTP request to App Router endpoints
  • CVE-2025-55183 (Medium) - Source Code Exposure of Server Actions

Reference

https://github.com/vercel/next.js/security/advisories

@benfrank241

Copy link
Copy Markdown
Member

Closing as superseded: main is now on next@^15.5.18, which is newer than the 15.5.9 proposed here and already includes the CVE-2025-55184 / CVE-2025-55183 patches (and later fixes). This branch conflicts because main moved past it. Thanks @dcbouius — the upgrade landed via later bumps. Reopen if I've misread.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants