Skip to content

fix(deps): patch Next.js SSRF/DoS CVEs and nanoid/undici/axios advisories - #1061

Merged
biwasxyz merged 3 commits into
mainfrom
fix/security-bump-next-15.5.21
Sep 1, 2026
Merged

biwasxyz merged 3 commits into
mainfrom
fix/security-bump-next-15.5.21

Conversation

@biwasxyz

@biwasxyz biwasxyz commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Patches the highest-severity open Dependabot alerts. next is the reason this is urgent: three high-severity advisories on a public surface, unpatched since 15.5.18.

Next.js ^15.5.18 to ^15.5.21 (resolves 15.5.25)

CVE Severity Issue
CVE-2026-64645 high DoS in App Router via Server Actions
CVE-2026-64641 high SSRF in Server Actions on custom servers
CVE-2026-64649 high SSRF in rewrites via attacker-controlled destination hostname

Plus five mediums: image-optimizer SVG DoS, response-body cache confusion (including on invalid UTF-8), unauthenticated disclosure of internal Server Function endpoints, and unbounded Server Action payload on Edge.

This deliberately stays on the 15.x line. See the note on #1053 below.

Override changes

Package Before After Resolves to Fixes
undici >=7.24.0 >=7.29.0 7.29.0 CVE-2026-12151, 13697, 6734, 9697
axios >=1.17.0 >=1.18.1 1.20.0 GHSA-gcfj-64vw-6mp9 (high) + 9 mediums
nanoid (none) >=3.3.18 <4 3.3.18 CVE-2026-67213, CVE-2026-67214
postcss (none) >=8.5.23 8.5.26 CVE-2026-45623, CVE-2026-73646 + medium

Two things worth knowing if these ranges are ever revisited:

  1. The nanoid upper bound <4 is load-bearing. An open-ended >=3.3.18 resolves to 6.0.1, which is ESM-only and breaks the CJS require inside postcss.
  2. nanoid 3.3.16 is not sufficient. It fixes CVE-2026-67214 only; CVE-2026-67213 needs >= 3.3.18.

Verification

  • 1541 tests pass, 5 skipped, across 101 files
  • npm run lint clean (only pre-existing <img> warnings)
  • npm run build succeeds
  • npm run typecheck reports 150 errors, all pre-existing. Verified by building an isolated git worktree of main, installing its deps, and diffing the sorted error sets: byte-identical, zero new type errors.
  • CSS output is byte-identical to main (same content-hash filename 72ff8b18a86d1200.css, same 121372 bytes, same SHA256). This matters because next pins postcss to exactly 8.4.31 and the override forces 8.5.26, so the CSS pipeline was verified rather than assumed.

Superseded PRs

Closed in favour of this one, each with a reason on the PR:

#1029 stays open for its wrangler bump; only its undici half is superseded (and it targeted 7.28.0, which still leaves CVE-2026-13697 open).

Review notes

Every advisory threshold was checked programmatically against the resolved versions rather than assumed. The postcss floor started at >=8.5.18, which cleared the two highs but sat under the >=8.5.23 threshold for the sibling medium; it resolved to 8.5.26 regardless, but the floor was raised so the range expresses intent instead of relying on npm picking the newest match.

…ries

Bumps next to ^15.5.21 (resolves 15.5.25), closing three high-severity
runtime advisories on a public surface:

  CVE-2026-64645  DoS in App Router via Server Actions
  CVE-2026-64641  SSRF in Server Actions on custom servers
  CVE-2026-64649  SSRF in rewrites via attacker-controlled destination host

plus five mediums (image-optimizer SVG DoS, response-body cache confusion,
unauthenticated disclosure of internal Server Function endpoints).

Tightens three existing overrides:

  undici  >=7.24.0 -> >=7.29.0   CVE-2026-12151, 13697, 6734, 9697
  axios   >=1.17.0 -> >=1.18.1   GHSA-gcfj-64vw-6mp9 + 9 mediums
  nanoid  (new) >=3.3.18 <4      CVE-2026-67213, CVE-2026-67214

The nanoid range is upper-bounded at <4 deliberately. An open-ended
>=3.3.18 resolves to 6.x, which is ESM-only and breaks the CJS require
in postcss.

Verified: 1541 tests pass, lint clean, production build succeeds.
Typecheck reports 150 errors, all pre-existing and identical on main.
Resolves postcss@8.5.26 across next and @tailwindcss/postcss. Covers the
build-time half of #1053 without taking its next 15 -> 16 major bump.
The >=8.5.18 floor cleared the two high advisories but sat below the
>=8.5.23 threshold for CVE-2026-73646's sibling medium. Resolution landed
on 8.5.26 either way, so this expresses intent rather than relying on npm
picking the newest match. Lockfile and CSS output are unchanged.
@biwasxyz
biwasxyz merged commit e6424ce into main Sep 1, 2026
8 checks passed
@biwasxyz
biwasxyz deleted the fix/security-bump-next-15.5.21 branch September 1, 2026 15:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant