
Critical Next.js Flaws Let Attackers Bypass Authentication and Launch SSRF Attacks
Vercel has disclosed nine security vulnerabilities in Next.js, the widely used React framework, including two critical-severity flaws that allow attackers to bypass authentication middleware and hijack server-side requests. The advisories, published by researcher KarimPwnz, affect versions ranging from 12.0.0 through 16.2.10, with patches available in 15.5.21 and 16.2.11. The most severe issue, tracked as CVE-2026-64642 […]
The post Critical Next.js Flaws Let Attackers Bypass Authentication and Launch SSRF Attacks appeared first on Cyber Security News.