megachangelog
Security15.5.18, 16.2.6

Next.js May 2026 security release

A coordinated security release addressing 13 critical and moderate vulnerabilities including denial of service, middleware and proxy bypass, server-side request forgery, cache poisoning, and cross-site scripting across Next.js and React. All affected users should upgrade immediately to the patched versions.

Summary

We have shipped a coordinated security release for Next.js addressing 13 advisories across denial of service, middleware and proxy bypass, server-side request forgery, cache poisoning, and cross-site scripting. One advisory addresses an upstream React Server Components vulnerability tracked as . CVE-2026-23870

Patched versions are available for both React and Next.js, and all should upgrade immediately.affected users

The release addresses the following advisories:

Affects applications that rely on or for authorization.middleware.jsproxy.js

Affects applications using Server Functions, Partial Prerendering with Cache Components, or the Image Optimization API.

Affects applications that handle WebSocket upgrade requests.

Affects applications with caching layers in front of React Server Component responses.

Affects applications using CSP nonces in App Router, or scripts that consume untrusted input.beforeInteractive

These vulnerabilities are addressed by the patched releases of React and Next.js. Patching is the only complete mitigation, and all should upgrade immediately. affected users

Vercel has not deployed new WAF rules for this release; these advisories cannot be reliably blocked at the WAF layer.

Frameworks and bundlers using packages should install the latest versions provided by their respective maintainers.react-server-dom-*

Read more

Recommended actions

Middleware and proxy bypass

Denial of service

Server-side request forgery

Cache poisoning

Cross-site scripting

Impact

Resolution

Affected versions

Fixed in

References

Package

Affected

Upgrade to

, Next.js 13.x14.x

all versions

or 15.5.1816.2.6

Next.js 15.x

<=15.5.17

15.5.18

Next.js 16.x

<=16.2.5

16.2.6

react-server-dom-*19.0.x

<=19.0.5

19.0.6

react-server-dom-*19.1.x

<=19.1.6

19.1.7

react-server-dom-*19.2.x

<=19.2.5

19.2.6

securitynextjsreactvulnerabilitydenial-of-servicexss

Source: original entry ↗