Skip to content

Bump next to 16.2.5 [SECURITY] - autoclosed - #4585

Closed
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-next-vulnerability
Closed

Bump next to 16.2.5 [SECURITY] - autoclosed#4585
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-next-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Apr 11, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
next (source) 16.1.716.2.5 age confidence

Next.js has a Denial of Service with Server Components

GHSA-q4gf-8mx6-v5v3

More information

Details

A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as CVE-2026-23869. You can read more about this advisory our this changelog.

A specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of service in unpatched environments.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Next.js Vulnerable to Denial of Service with Server Components

GHSA-8h8q-6873-q5fj

More information

Details

A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as CVE-2026-23870.

A specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of service in unpatched environments.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

vercel/next.js (next)

v16.2.5

Compare Source

v16.2.4

Compare Source

v16.2.3

Compare Source

v16.2.2

Compare Source

v16.2.1

Compare Source

v16.2.0

Compare Source


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Update of dependencies. security Pull requests that address a security vulnerability. labels Apr 11, 2026
@renovate
renovate Bot requested a review from atomiks as a code owner April 11, 2026 05:41
@renovate renovate Bot added the security Pull requests that address a security vulnerability. label Apr 11, 2026
@pkg-pr-new

pkg-pr-new Bot commented Apr 11, 2026

Copy link
Copy Markdown

commit: 2a7e8a0

@code-infra-dashboard

code-infra-dashboard Bot commented Apr 11, 2026

Copy link
Copy Markdown

Bundle size

Bundle Parsed size Gzip size
@base-ui/react 0B(0.00%) 0B(0.00%)

Details of bundle changes

Performance

Total duration: 1,213.10 ms +110.20 ms(+10.0%) | Renders: 50 (+0) | Paint: 1,859.13 ms +197.28 ms(+11.9%)

Test Duration Renders
Scroll Area mount (300 instances) 101.23 ms 🔺+22.61 ms(+28.8%) 3 (+0)
Checkbox mount (500 instances) 74.87 ms 🔺+15.77 ms(+26.7%) 1 (+0)
Dialog mount (300 instances) 53.66 ms 🔺+10.18 ms(+23.4%) 1 (+0)

details


Check out the code infra dashboard for more information about this PR.

@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 3ed194e to b39699b Compare April 16, 2026 07:56
@github-actions github-actions Bot added the PR: out-of-date The pull request has merge conflicts and can't be merged. label Apr 17, 2026
@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch from b39699b to 4d58e11 Compare April 17, 2026 10:43
@github-actions github-actions Bot added PR: out-of-date The pull request has merge conflicts and can't be merged. and removed PR: out-of-date The pull request has merge conflicts and can't be merged. labels Apr 17, 2026
@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 4d58e11 to 5d69445 Compare April 21, 2026 12:43
@github-actions github-actions Bot added PR: out-of-date The pull request has merge conflicts and can't be merged. and removed PR: out-of-date The pull request has merge conflicts and can't be merged. labels Apr 21, 2026
@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 5d69445 to ff33999 Compare April 23, 2026 18:25
@github-actions github-actions Bot removed the PR: out-of-date The pull request has merge conflicts and can't be merged. label Apr 23, 2026
@bernardobelchior

Copy link
Copy Markdown
Member

Wait to see how Base UI solves it: #4585

@michaldudak

Copy link
Copy Markdown
Member

Blocked due to vercel/next.js#91735 (same as #4394)

@michaldudak michaldudak added the on hold There is a blocker, we need to wait. label Apr 27, 2026
@github-actions github-actions Bot added the PR: out-of-date The pull request has merge conflicts and can't be merged. label Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch from ff33999 to a989132 Compare April 27, 2026 08:09
@github-actions github-actions Bot added PR: out-of-date The pull request has merge conflicts and can't be merged. and removed PR: out-of-date The pull request has merge conflicts and can't be merged. labels Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch from a989132 to 95616d5 Compare April 27, 2026 08:15
@github-actions github-actions Bot added PR: out-of-date The pull request has merge conflicts and can't be merged. and removed PR: out-of-date The pull request has merge conflicts and can't be merged. labels Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 95616d5 to 21ffaa6 Compare April 27, 2026 08:28
@github-actions github-actions Bot removed the PR: out-of-date The pull request has merge conflicts and can't be merged. label Apr 27, 2026
@renovate renovate Bot changed the title Bump next to 16.2.3 [SECURITY] Bump next to 16.2.3 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate
renovate Bot deleted the renovate/npm-next-vulnerability branch April 27, 2026 21:09
@renovate renovate Bot changed the title Bump next to 16.2.3 [SECURITY] - autoclosed Bump next to 16.2.3 [SECURITY] Apr 28, 2026
@renovate renovate Bot reopened this Apr 28, 2026
@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch 2 times, most recently from 21ffaa6 to 15e1808 Compare April 28, 2026 04:25
@github-actions github-actions Bot added the PR: out-of-date The pull request has merge conflicts and can't be merged. label Apr 28, 2026
@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 15e1808 to bcdf98b Compare April 28, 2026 20:35
@github-actions github-actions Bot removed the PR: out-of-date The pull request has merge conflicts and can't be merged. label Apr 28, 2026
@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch from bcdf98b to de3da3a Compare April 29, 2026 10:24
@github-actions github-actions Bot added the PR: out-of-date The pull request has merge conflicts and can't be merged. label May 11, 2026
@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch from de3da3a to 0377695 Compare May 11, 2026 14:32
@github-actions github-actions Bot added PR: out-of-date The pull request has merge conflicts and can't be merged. and removed PR: out-of-date The pull request has merge conflicts and can't be merged. labels May 11, 2026
@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 0377695 to 2a7e8a0 Compare May 11, 2026 15:09
@renovate renovate Bot changed the title Bump next to 16.2.3 [SECURITY] Bump next to 16.2.5 [SECURITY] May 11, 2026
@github-actions github-actions Bot added PR: out-of-date The pull request has merge conflicts and can't be merged. and removed PR: out-of-date The pull request has merge conflicts and can't be merged. labels May 11, 2026
@renovate renovate Bot changed the title Bump next to 16.2.5 [SECURITY] Bump next to 16.2.5 [SECURITY] - autoclosed Jun 12, 2026
@renovate renovate Bot closed this Jun 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Update of dependencies. on hold There is a blocker, we need to wait. PR: out-of-date The pull request has merge conflicts and can't be merged. security Pull requests that address a security vulnerability.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants