fix(deps): update dependency next to v15.2.4 [security]#352
fix(deps): update dependency next to v15.2.4 [security]#352renovate[bot] wants to merge 1 commit into
Conversation
✅ Deploy Preview for celo-composer ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
f4121fd to
6e7dc1b
Compare
6e7dc1b to
e91b7be
Compare
e91b7be to
79cf38c
Compare
|
Caution Review the following alerts detected in dependencies. According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.
|
79cf38c to
e8e5576
Compare
8af659a to
25b2f86
Compare
25b2f86 to
19df5b4
Compare
19df5b4 to
812cad9
Compare
812cad9 to
7f4774e
Compare
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
7f4774e to
c30444a
Compare
This PR contains the following updates:
15.2.3->15.2.4GitHub Vulnerability Alerts
CVE-2025-30218
Summary
In the process of remediating CVE-2025-29927, we looked at other possible exploits of Middleware. We independently verified this low severity vulnerability in parallel with two reports from independent researchers.
Learn more here.
Credit
Thank you to Jinseo Kim kjsman and RyotaK (GMO Flatt Security Inc.) with takumi-san.ai for the responsible disclosure. These researchers were awarded as part of our bug bounty program.
Next.js may leak x-middleware-subrequest-id to external hosts
CVE-2025-30218 / GHSA-223j-4rm8-mrmf
More information
Details
Summary
In the process of remediating CVE-2025-29927, we looked at other possible exploits of Middleware. We independently verified this low severity vulnerability in parallel with two reports from independent researchers.
Learn more here.
Credit
Thank you to Jinseo Kim kjsman and RyotaK (GMO Flatt Security Inc.) with takumi-san.ai for the responsible disclosure. These researchers were awarded as part of our bug bounty program.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:UReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
vercel/next.js (next)
v15.2.4Compare Source
Core Changes
Credits
Huge thanks to @ijjk and @ztanner for helping!
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.