-
Notifications
You must be signed in to change notification settings - Fork 419
chore(nextjs): Update dependency next to v14.2.25 [SECURITY] #5418
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
|
bfe9216 to
c8a08d8
Compare
c8a08d8 to
27d9c45
Compare
27d9c45 to
10438cf
Compare
10438cf to
2488d7e
Compare
2488d7e to
a593f74
Compare
a593f74 to
1519a93
Compare
1519a93 to
c3461e3
Compare
Pull request was closed
c3461e3 to
57d0b34
Compare
57d0b34 to
5a41f3b
Compare
c534de9 to
d18c5bc
Compare
d18c5bc to
fe9f5fb
Compare
fe9f5fb to
b1e805c
Compare
b1e805c to
a5a4ac0
Compare
a5a4ac0 to
5f84c46
Compare
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
This PR contains the following updates:
14.2.24->14.2.25Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
GitHub Vulnerability Alerts
CVE-2025-29927
Impact
It is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware.
Patches
15.2.314.2.2513.5.912.3.5Note: Next.js deployments hosted on Vercel are automatically protected against this vulnerability.
Workaround
If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the
x-middleware-subrequestheader from reaching your Next.js application.Credits
Release Notes
vercel/next.js (next)
v14.2.25Compare Source
Configuration
📅 Schedule: Branch creation - "" in timezone GMT, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.