Skip to content

🚨 [security] Update all of nextjs 12.1.0 β†’ 16.2.6 (major)#324

Open
depfu[bot] wants to merge 1 commit into
mainfrom
depfu/update/yarn/group/nextjs-16.2.6
Open

🚨 [security] Update all of nextjs 12.1.0 β†’ 16.2.6 (major)#324
depfu[bot] wants to merge 1 commit into
mainfrom
depfu/update/yarn/group/nextjs-16.2.6

Conversation

@depfu
Copy link
Copy Markdown
Contributor

@depfu depfu Bot commented May 11, 2026


🚨 Your current dependencies have known security vulnerabilities 🚨

This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!


Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.

What changed?

✳️ eslint-config-next (12.1.6 β†’ 16.2.6)

Sorry, we couldn't find anything useful about this release.

✳️ next (12.1.0 β†’ 16.2.6) Β· Repo

Security Advisories 🚨

🚨 Next.js Vulnerable to Denial of Service with Server Components

More info than we can show here.

🚨 Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes

More info than we can show here.

🚨 Next.js vulnerable to cache poisoning in React Server Component responses

More info than we can show here.

🚨 Next.js vulnerable to cache poisoning in React Server Component responses

More info than we can show here.

🚨 Next.js has a Middleware / Proxy bypass through dynamic route parameter injection

More info than we can show here.

🚨 Next.js has a Middleware / Proxy bypass through dynamic route parameter injection

More info than we can show here.

🚨 Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades

More info than we can show here.

🚨 Next.js has a Denial of Service in the Image Optimization API

More info than we can show here.

🚨 Next.js has a Denial of Service in the Image Optimization API

More info than we can show here.

🚨 Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components

More info than we can show here.

🚨 Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components

More info than we can show here.

🚨 Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

More info than we can show here.

🚨 Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

More info than we can show here.

🚨 Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

More info than we can show here.

🚨 Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces

More info than we can show here.

🚨 Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces

More info than we can show here.

🚨 Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n

More info than we can show here.

🚨 Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n

More info than we can show here.

🚨 Next.js Vulnerable to Denial of Service with Server Components

More info than we can show here.

🚨 Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

More info than we can show here.

🚨 Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades

More info than we can show here.

🚨 Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes

More info than we can show here.

🚨 Next.js has a Denial of Service with Server Components

More info than we can show here.

🚨 Next.js has a Denial of Service with Server Components

More info than we can show here.

🚨 Next.js: HTTP request smuggling in rewrites

More info than we can show here.

🚨 Next.js: Unbounded next/image disk cache growth can exhaust storage

More info than we can show here.

🚨 Next.js: HTTP request smuggling in rewrites

More info than we can show here.

🚨 Next.js: Unbounded next/image disk cache growth can exhaust storage

More info than we can show here.

🚨 Next.js: Unbounded postponed resume buffering can lead to DoS

More info than we can show here.

🚨 Next.js: null origin can bypass Server Actions CSRF checks

More info than we can show here.

🚨 Next.js: null origin can bypass dev HMR websocket CSRF checks

More info than we can show here.

🚨 Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

More info than we can show here.

🚨 Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

More info than we can show here.

🚨 Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

More info than we can show here.

🚨 Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

More info than we can show here.

🚨 Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

More info than we can show here.

🚨 Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

More info than we can show here.

🚨 Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

More info than we can show here.

🚨 Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

More info than we can show here.

🚨 Next.js has Unbounded Memory Consumption via PPR Resume Endpoint

More info than we can show here.

🚨 Next.js has Unbounded Memory Consumption via PPR Resume Endpoint

More info than we can show here.

🚨 Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

More info than we can show here.

🚨 Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

More info than we can show here.

🚨 Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

More info than we can show here.

🚨 Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

More info than we can show here.

🚨 Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

More info than we can show here.

🚨 Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

More info than we can show here.

🚨 Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

More info than we can show here.

🚨 Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

More info than we can show here.

🚨 Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

More info than we can show here.

🚨 Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

More info than we can show here.

🚨 Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

More info than we can show here.

🚨 Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

More info than we can show here.

🚨 Next Server Actions Source Code Exposure

More info than we can show here.

🚨 Next Vulnerable to Denial of Service with Server Components

More info than we can show here.

🚨 Next Vulnerable to Denial of Service with Server Components

More info than we can show here.

🚨 Next Vulnerable to Denial of Service with Server Components

More info than we can show here.

🚨 Next Vulnerable to Denial of Service with Server Components

More info than we can show here.

🚨 Next Vulnerable to Denial of Service with Server Components

More info than we can show here.

🚨 Next Vulnerable to Denial of Service with Server Components

More info than we can show here.

🚨 Next Vulnerable to Denial of Service with Server Components

More info than we can show here.

🚨 Next Vulnerable to Denial of Service with Server Components

More info than we can show here.

🚨 Next Vulnerable to Denial of Service with Server Components

More info than we can show here.

🚨 Next Server Actions Source Code Exposure

More info than we can show here.

🚨 Next Server Actions Source Code Exposure

More info than we can show here.

🚨 Next Server Actions Source Code Exposure

More info than we can show here.

🚨 Next Server Actions Source Code Exposure

More info than we can show here.

🚨 Next Server Actions Source Code Exposure

More info than we can show here.

🚨 Next Server Actions Source Code Exposure

More info than we can show here.

🚨 Next Server Actions Source Code Exposure

More info than we can show here.

🚨 Next.js is vulnerable to RCE in React flight protocol

More info than we can show here.

🚨 Next.js is vulnerable to RCE in React flight protocol

More info than we can show here.

🚨 Next.js is vulnerable to RCE in React flight protocol

More info than we can show here.

🚨 Next.js is vulnerable to RCE in React flight protocol

More info than we can show here.

🚨 Next.js is vulnerable to RCE in React flight protocol

More info than we can show here.

🚨 Next.js is vulnerable to RCE in React flight protocol

More info than we can show here.

🚨 Next.js is vulnerable to RCE in React flight protocol

More info than we can show here.

🚨 Next.js Improper Middleware Redirect Handling Leads to SSRF

More info than we can show here.

🚨 Next.js Improper Middleware Redirect Handling Leads to SSRF

More info than we can show here.

🚨 Next.js Affected by Cache Key Confusion for Image Optimization API Routes

More info than we can show here.

🚨 Next.js Content Injection Vulnerability for Image Optimization

More info than we can show here.

🚨 Next.js Content Injection Vulnerability for Image Optimization

More info than we can show here.

🚨 Next.JS vulnerability can lead to DoS via cache poisoning

More info than we can show here.

🚨 Next.js has a Cache poisoning vulnerability due to omission of the Vary header

More info than we can show here.

🚨 Information exposure in Next.js dev server due to lack of origin verification

More info than we can show here.

🚨 Information exposure in Next.js dev server due to lack of origin verification

More info than we can show here.

🚨 Next.js Race Condition to Cache Poisoning

More info than we can show here.

🚨 Next.js Race Condition to Cache Poisoning

More info than we can show here.

🚨 Next.js may leak x-middleware-subrequest-id to external hosts

More info than we can show here.

🚨 Next.js may leak x-middleware-subrequest-id to external hosts

More info than we can show here.

🚨 Next.js may leak x-middleware-subrequest-id to external hosts

More info than we can show here.

🚨 Next.js may leak x-middleware-subrequest-id to external hosts

More info than we can show here.

🚨 Authorization Bypass in Next.js Middleware

More info than we can show here.

🚨 Authorization Bypass in Next.js Middleware

More info than we can show here.

🚨 Authorization Bypass in Next.js Middleware

More info than we can show here.

🚨 Authorization Bypass in Next.js Middleware

More info than we can show here.

🚨 Next.js Allows a Denial of Service (DoS) with Server Actions

More info than we can show here.

🚨 Next.js Allows a Denial of Service (DoS) with Server Actions

More info than we can show here.

🚨 Next.js Allows a Denial of Service (DoS) with Server Actions

More info than we can show here.

🚨 Next.js authorization bypass vulnerability

More info than we can show here.

🚨 Denial of Service condition in Next.js image optimization

More info than we can show here.

🚨 Next.js Cache Poisoning

More info than we can show here.

🚨 Next.js Cache Poisoning

More info than we can show here.

🚨 Next.js Denial of Service (DoS) condition

More info than we can show here.

🚨 Next.js Vulnerable to HTTP Request Smuggling

More info than we can show here.

🚨 Next.js Server-Side Request Forgery in Server Actions

More info than we can show here.

🚨 Next.js missing cache-control header may lead to CDN caching empty reply

More info than we can show here.

🚨 Unexpected server crash in Next.js

More info than we can show here.
Release Notes

Too many releases to show here. View the full release notes.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.


Depfu Status

Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with @depfu rebase.

All Depfu comment commands
@​depfu rebase
Rebases against your default branch and redoes this update
@​depfu recreate
Recreates this PR, overwriting any edits that you've made to it
@​depfu merge
Merges this PR once your tests are passing and conflicts are resolved
@​depfu cancel merge
Cancels automatic merging of this PR
@​depfu close
Closes this PR and deletes the branch
@​depfu reopen
Restores the branch and reopens this PR (if it's closed)
@​depfu pause
Ignores all future updates for this dependency and closes this PR
@​depfu pause [minor|major]
Ignores all future minor/major updates for this dependency and closes this PR
@​depfu resume
Future versions of this dependency will create PRs again (leaves this PR as is)

@depfu depfu Bot added the dependencies Pull requests that update a dependency file label May 11, 2026
@depfu depfu Bot requested a review from maltejur as a code owner May 11, 2026 16:18
@depfu depfu Bot force-pushed the depfu/update/yarn/group/nextjs-16.2.6 branch from f13230c to 86ce717 Compare May 11, 2026 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants