Skip to content

fix: bump next to 16.1.5 for security fix#79

Merged
cbullinger merged 1 commit intodevelopmentfrom
dependabot-23-dev
Jan 28, 2026
Merged

fix: bump next to 16.1.5 for security fix#79
cbullinger merged 1 commit intodevelopmentfrom
dependabot-23-dev

Conversation

@cbullinger
Copy link
Collaborator

@cbullinger cbullinger commented Jan 28, 2026

Summary

Addresses Dependabot security alert #23 by bumping Next.js.

Changes

  • next: 16.0.1016.1.5 (CVE-2025-59471 fix per Dependabot alert #23)
  • eslint-config-next: 16.0.1016.1.5 (matching version)

Vulnerability Details

  • CVE: CVE-2025-59471
  • GHSA: GHSA-9g9p-9gw9-jx7f
  • Severity: Medium (CVSS 5.9)
  • Description: DoS vulnerability in self-hosted Next.js applications via Image Optimizer remotePatterns configuration

Testing

  • npm install completes successfully with 0 vulnerabilities
  • npm run build compiles successfully
  • npm run start runs correctly with Next.js 16.1.5

CVE fix per Dependabot alert #23
Copy link
Collaborator

@dacharyc dacharyc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@cbullinger cbullinger merged commit ce1e9b2 into development Jan 28, 2026
1 check passed
@cbullinger cbullinger deleted the dependabot-23-dev branch February 9, 2026 20:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants