Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks

Vercel has disclosed and patched nine security vulnerabilities in Next.js, the widely used React framework, addressing flaws that could enable server-side request forgery (SSRF), middleware authentication bypass, denial-of-service (DoS) attacks, and sensitive data exposure. All nine advisories were published two days ago by security researcher KarimPwnz and are now fixed in Next.js versions 15.5.21 and […]

The post Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: