Skip to content

v3.31.0

Latest

Choose a tag to compare

@goklab goklab released this 23 Jul 19:04
  • Critical Auth.js pair: v5-beta fail-open authorization bypass and homoglyph '@' email normalization bypass (GHSA-8fpg-xm3f-6cx3 / GHSA-7rqj-j65f-68wh), plus the @clerk/nextjs 5.x middleware bypass window no rule covered (CVE-2026-41248)
  • July residual-window pins: Next.js Server Actions/rewrites SSRF cluster (CVE-2026-64649 et al., fix 15.5.21/16.2.11) and PostCSS sourceMappingURL arbitrary file read (CVE-2026-45623, fix 8.5.12)
  • New IOC rule for the @asyncapi/* supply-chain compromise (five malicious versions across four packages, import-time payload)