fix(deps): patch Next.js SSRF/DoS CVEs and nanoid/undici/axios advisories - #1061
Merged
Merged
Conversation
…ries Bumps next to ^15.5.21 (resolves 15.5.25), closing three high-severity runtime advisories on a public surface: CVE-2026-64645 DoS in App Router via Server Actions CVE-2026-64641 SSRF in Server Actions on custom servers CVE-2026-64649 SSRF in rewrites via attacker-controlled destination host plus five mediums (image-optimizer SVG DoS, response-body cache confusion, unauthenticated disclosure of internal Server Function endpoints). Tightens three existing overrides: undici >=7.24.0 -> >=7.29.0 CVE-2026-12151, 13697, 6734, 9697 axios >=1.17.0 -> >=1.18.1 GHSA-gcfj-64vw-6mp9 + 9 mediums nanoid (new) >=3.3.18 <4 CVE-2026-67213, CVE-2026-67214 The nanoid range is upper-bounded at <4 deliberately. An open-ended >=3.3.18 resolves to 6.x, which is ESM-only and breaks the CJS require in postcss. Verified: 1541 tests pass, lint clean, production build succeeds. Typecheck reports 150 errors, all pre-existing and identical on main.
Resolves postcss@8.5.26 across next and @tailwindcss/postcss. Covers the build-time half of #1053 without taking its next 15 -> 16 major bump.
This was referenced Sep 1, 2026
The >=8.5.18 floor cleared the two high advisories but sat below the >=8.5.23 threshold for CVE-2026-73646's sibling medium. Resolution landed on 8.5.26 either way, so this expresses intent rather than relying on npm picking the newest match. Lockfile and CSS output are unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Patches the highest-severity open Dependabot alerts.
nextis the reason this is urgent: three high-severity advisories on a public surface, unpatched since 15.5.18.Next.js
^15.5.18to^15.5.21(resolves 15.5.25)Plus five mediums: image-optimizer SVG DoS, response-body cache confusion (including on invalid UTF-8), unauthenticated disclosure of internal Server Function endpoints, and unbounded Server Action payload on Edge.
This deliberately stays on the 15.x line. See the note on #1053 below.
Override changes
undici>=7.24.0>=7.29.0axios>=1.17.0>=1.18.1nanoid>=3.3.18 <4postcss>=8.5.23Two things worth knowing if these ranges are ever revisited:
<4is load-bearing. An open-ended>=3.3.18resolves to6.0.1, which is ESM-only and breaks the CJSrequireinside postcss.3.3.16is not sufficient. It fixes CVE-2026-67214 only; CVE-2026-67213 needs>= 3.3.18.Verification
npm run lintclean (only pre-existing<img>warnings)npm run buildsucceedsnpm run typecheckreports 150 errors, all pre-existing. Verified by building an isolatedgit worktreeofmain, installing its deps, and diffing the sorted error sets: byte-identical, zero new type errors.main(same content-hash filename72ff8b18a86d1200.css, same 121372 bytes, same SHA256). This matters becausenextpinspostcssto exactly8.4.31and the override forces8.5.26, so the CSS pipeline was verified rather than assumed.Superseded PRs
Closed in favour of this one, each with a reason on the PR:
nextto^16.3.0, a 15 to 16 major migration rather than a security patch. The postcss half is covered here. Next 16 upgrade tracked separately in Upgrade Next.js 15 to 16 #1062.#1029 stays open for its
wranglerbump; only its undici half is superseded (and it targeted 7.28.0, which still leaves CVE-2026-13697 open).Review notes
Every advisory threshold was checked programmatically against the resolved versions rather than assumed. The postcss floor started at
>=8.5.18, which cleared the two highs but sat under the>=8.5.23threshold for the sibling medium; it resolved to 8.5.26 regardless, but the floor was raised so the range expresses intent instead of relying on npm picking the newest match.