Next.js version 15.2.3 addresses the CVE-2025-29927 security vulnerability. Self-hosted deployments using `next start` and `output: 'standalone'` should update immediately. Applications on Vercel, Netlify, and Cloudflare are unaffected. The vulnerability involved bypassing Middleware checks, potentially skipping critical validations. Patches are available for versions 12, 13, 14, and 15.

2m read timeFrom nextjs.org
Post cover image
Table of contents
TimelineVulnerability detailsImpact scopePatched versionsOur security responsibility

Sort: