Skip to content

Update dependency next to v16.2.3 [SECURITY]#6252

Merged
joshwooding merged 2 commits into
mainfrom
renovate/npm-next-vulnerability
Apr 27, 2026
Merged

Update dependency next to v16.2.3 [SECURITY]#6252
joshwooding merged 2 commits into
mainfrom
renovate/npm-next-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 11, 2026

This PR contains the following updates:

Package Change Age Confidence
next (source) 16.1.716.2.3 age confidence

Next.js has a Denial of Service with Server Components

GHSA-q4gf-8mx6-v5v3

More information

Details

A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as CVE-2026-23869. You can read more about this advisory our this changelog.

A specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of service in unpatched environments.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

vercel/next.js (next)

v16.2.3

Compare Source

v16.2.2

Compare Source

v16.2.1

Compare Source

v16.2.0

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@vercel
Copy link
Copy Markdown

vercel Bot commented Apr 11, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
saltdesignsystem Ready Ready Preview, Comment Apr 27, 2026 10:29pm

Request Review

@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented Apr 11, 2026

⚠️ No Changeset found

Latest commit: 95442a3

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 5e5f2b0 to 30579ad Compare April 14, 2026 05:41
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 30579ad to 2c628b1 Compare April 14, 2026 12:41
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 2c628b1 to d1058d7 Compare April 14, 2026 15:46
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from d1058d7 to 3c86a67 Compare April 14, 2026 20:45
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 3c86a67 to 5766059 Compare April 15, 2026 13:27
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch 2 times, most recently from e238dd9 to e4ff63b Compare April 15, 2026 20:54
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from e4ff63b to 63a4d11 Compare April 20, 2026 14:35
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 63a4d11 to 3e531fb Compare April 22, 2026 10:56
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 3e531fb to 6e0bce1 Compare April 22, 2026 23:45
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 6e0bce1 to 420fdb5 Compare April 23, 2026 15:11
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 420fdb5 to 010befb Compare April 23, 2026 20:59
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 010befb to 591aff4 Compare April 23, 2026 23:06
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 591aff4 to 4b0427a Compare April 27, 2026 09:45
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 4b0427a to 55fd035 Compare April 27, 2026 09:59
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 55fd035 to 1e77b2d Compare April 27, 2026 10:35
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch 3 times, most recently from 7fe75f3 to 6454e38 Compare April 27, 2026 13:10
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch from 6454e38 to 4e7ad1b Compare April 27, 2026 14:03
@renovate renovate Bot changed the title Update dependency next to v16.2.3 [SECURITY] Update dependency next to v16.2.3 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot deleted the renovate/npm-next-vulnerability branch April 27, 2026 17:29
@renovate renovate Bot changed the title Update dependency next to v16.2.3 [SECURITY] - autoclosed Update dependency next to v16.2.3 [SECURITY] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate renovate Bot force-pushed the renovate/npm-next-vulnerability branch 2 times, most recently from 4e7ad1b to cedd4ad Compare April 27, 2026 20:46
@joshwooding joshwooding added the chromatic Run chromatic on the current PR. Will be removed by the CI once submitted. label Apr 27, 2026
@joshwooding joshwooding merged commit e5bc81a into main Apr 27, 2026
10 of 12 checks passed
joshwooding added a commit that referenced this pull request Apr 27, 2026
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Josh Wooding <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chromatic Run chromatic on the current PR. Will be removed by the CI once submitted.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants