Skip to content

fix: upgrade Next.js to 15.5.18 for security vulnerabilities#17676

Open
sergical wants to merge 1 commit intomasterfrom
fix/nextjs-security-upgrade
Open

fix: upgrade Next.js to 15.5.18 for security vulnerabilities#17676
sergical wants to merge 1 commit intomasterfrom
fix/nextjs-security-upgrade

Conversation

@sergical
Copy link
Copy Markdown
Member

@sergical sergical commented May 7, 2026

DESCRIBE YOUR PR

Upgrades Next.js from ^15.5.14 to ^15.5.18 to address 13 critical and high-severity CVEs disclosed on 2026-05-06.

Key vulnerabilities addressed:

References:

Changes:

  • package.json: bumped next from ^15.5.14 to ^15.5.18
  • pnpm-lock.yaml: updated lockfile accordingly

IS YOUR CHANGE URGENT?

Help us prioritize incoming PRs by letting us know when the change needs to go live.

  • Urgent deadline (GA date, etc.): ASAP — active security vulnerabilities
  • Other deadline:
  • None: Not urgent, can wait up to 1 week+

SLA

  • Teamwork makes the dream work, so please add a reviewer to your PRs.
  • Please give the docs team up to 1 week to review your PR unless you've added an urgent due date to it.
    Thanks in advance for your help!

PRE-MERGE CHECKLIST

Make sure you've checked the following before merging your changes:

  • Checked Vercel preview for correctness, including links
  • PR was reviewed and approved by any necessary SMEs (subject matter experts)
  • PR was reviewed and approved by a member of the Sentry docs team

Addresses 13 CVEs disclosed 2026-05-06 including:
- GHSA-26hh-7cqf-hhc6 (High): Middleware bypass via segment-prefetch
- GHSA-492v-c6pp-mqqv (High): Middleware bypass via dynamic route injection
- GHSA-c4j6-fc7j-m34r (High): SSRF via WebSocket upgrades
- GHSA-8h8q-6873-q5fj (High): DoS with Server Components
- GHSA-mg66-mrh9-m8jx (High): DoS via Cache Components
- CVE-2026-23870 (High): React Server Components DoS

See: https://developers.cloudflare.com/changelog/post/2026-05-06-react-nextjs-vulnerabilities/

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@vercel
Copy link
Copy Markdown

vercel Bot commented May 7, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
develop-docs Ready Ready Preview, Comment May 7, 2026 10:44pm
sentry-docs Ready Ready Preview, Comment May 7, 2026 10:44pm

Request Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant