Vercel has disclosed and patched nine security vulnerabilities in Next.js, the widely used React framework, addressing flaws that could enable server-side request forgery (SSRF), middleware authentication bypass, denial-of-service (DoS) attacks, and sensitive data exposure. All nine advisories were published two days ago by security researcher KarimPwnz and are now fixed in Next.js versions 15.5.21 and […]
The post Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks appeared first on Cyber Security News.
Read the original article: