Next.js version 15.2.3 addresses the CVE-2025-29927 security vulnerability. Self-hosted deployments using `next start` and `output: 'standalone'` should update immediately. Applications on Vercel, Netlify, and Cloudflare are unaffected. The vulnerability involved bypassing Middleware checks, potentially skipping critical

2m read timeFrom nextjs.org
Post cover image
Table of contents
TimelineVulnerability detailsImpact scopePatched versionsOur security responsibility

Sort: