// advisories
Is the stack on fire?
Open advisories from the GitHub Advisory Database, matched against the versions this site actually runs.
1 package exposed12 watched · just now
next16.3.0Exposed9 advisories · patch 16.3.8
- Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages · patched in 16.3.8MODERATE
- Next.js has cache poisoning of SSG and ISR pages in self-hosted applications · patched in 16.3.8MODERATE
- Next.js has information disclosure in development server's Model Context Protocol endpoint · patched in 16.3.8LOW
- Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass · patched in 16.3.8MODERATE
- Next.js has cache poisoning in SSG/ISR rendering that leads to cross-user content substitution and persistent denial of service · patched in 16.3.8MODERATE
- Next.js has Server-Side Request Forgery in Image Optimization · patched in 16.3.8HIGH
- Next.js: Remote Code Execution in next/og ImageResponse · patched in 16.3.6CRITICAL
- Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used · patched in 16.3.3CRITICAL
- Next.js: Unauthenticated Remote Code Execution on windows-hosted servers · patched in 16.3.3CRITICAL
163 further advisories on record, none reaching 16.3.0.
ai6.0.1972 advisories · all patched
drizzle-orm0.45.22 advisories · all patched
next-mdx-remote6.0.01 advisory · all patched
react19.2.63 advisories · all patched
react-dom19.2.65 advisories · all patched
- Cross-Site Scripting in react-dom · patched in 16.0.1MODERATE
- Cross-Site Scripting in react-dom · patched in 16.1.2MODERATE
- Cross-Site Scripting in react-dom · patched in 16.2.1MODERATE
- Cross-Site Scripting in react-dom · patched in 16.3.3MODERATE
- Cross-Site Scripting in react-dom · patched in 16.4.2MODERATE