Skip to content

fix: update next.js for CVE-2026-23864#25

Merged
leeandher merged 1 commit intogetsentry:mainfrom
sergical:fix/cve-2026-23864
Feb 12, 2026
Merged

fix: update next.js for CVE-2026-23864#25
leeandher merged 1 commit intogetsentry:mainfrom
sergical:fix/cve-2026-23864

Conversation

@sergical
Copy link
Member

Summary

Updates Next.js to address CVE-2026-23864 (DoS vulnerabilities in React Server Components).

Changes

  • next: 15.4.10 → 15.4.11

Vulnerability Details

The react-server-dom-* packages bundled with Next.js 15.4.x < 15.4.11 are vulnerable to DoS attacks via malicious HTTP requests to Server Function endpoints.

Verification

  • pnpm build passes

🤖 Generated with Claude Code

Updates:
- next: 15.4.10 → 15.4.11

Addresses DoS vulnerabilities in React Server Components bundled with Next.js.

Co-Authored-By: Claude <noreply@anthropic.com>
@sergical sergical requested a review from a team as a code owner January 28, 2026 00:04
@vercel
Copy link

vercel bot commented Jan 28, 2026

@sergical is attempting to deploy a commit to the Sentry Team on Vercel.

A member of the Team first needs to authorize it.

@vercel
Copy link

vercel bot commented Feb 12, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
error-generator Ready Ready Preview, Comment Feb 12, 2026 3:32pm

Request Review

@leeandher
Copy link
Member

thank you @sergical! merging for ongoing incident

@leeandher leeandher merged commit 5bb825f into getsentry:main Feb 12, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants