Skip to content

Update next to 16.2.11 - #508

Merged
twitchyliquid64 merged 1 commit into
mainfrom
update-next-16.2.11
Jul 22, 2026
Merged

Update next to 16.2.11#508
twitchyliquid64 merged 1 commit into
mainfrom
update-next-16.2.11

Conversation

@gominimal-pkgmgr-mgr

Copy link
Copy Markdown
Contributor

Update next 16.2.616.2.11

Source: github:vercel/next.js
Release: https://github.com/vercel/next.js/releases/tag/v16.2.11
Changelog: vercel/next.js@v16.2.6...v16.2.11
Released: 22 hours ago (2026-07-21)

Pkgscan: clean — diff against the prior version surfaced no newly-introduced suspicious patterns.

Vulnerability impact

Partition analysis at 16.2.11 (uses each advisory's fixed-version, vulnerable-range, affected-ranges, and fix-commit ancestry to decide):

  • 9 cleared — the new version is outside the advisory's affected range, OR the tag's lineage includes a known fix-commit. These will drop off the next scan.

Vulnerabilities fixed (9)

This update clears 9 vulnerabilities affecting 16.2.6:

CVE / GHSA Severity Fixed in
GHSA-6gpp-xcg3-4w24 HIGH 16.2.11
GHSA-89xv-2m56-2m9x HIGH 15.5.21
GHSA-m99w-x7hq-7vfj HIGH 15.5.21
GHSA-p9j2-gv94-2wf4 HIGH 15.5.21
GHSA-4633-3j49-mh5q MEDIUM 15.5.21
GHSA-4c39-4ccg-62r3 MEDIUM 15.5.21
GHSA-68g3-v927-f742 MEDIUM 15.5.21
GHSA-955p-x3mx-jcvp MEDIUM 15.5.21
GHSA-q8wf-6r8g-63ch MEDIUM 15.5.21
Advisory summaries
  • GHSA-6gpp-xcg3-4w24 — Middleware / Proxy bypass in App Router applications using Turbopack and single locale (Published 2026-07-21)
  • GHSA-89xv-2m56-2m9x — Server-Side Request Forgery in Server Actions on custom servers (Published 2026-07-21)
  • GHSA-m99w-x7hq-7vfj — Denial of Service in App Router using Server Actions (Published 2026-07-21)
  • GHSA-p9j2-gv94-2wf4 — Server-Side Request Forgery in rewrites via attacker-controlled destination hostname (Published 2026-07-21)
  • GHSA-4633-3j49-mh5q — Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences (Published 2026-07-21)
  • GHSA-4c39-4ccg-62r3 — Unbounded Server Action payload in Edge runtime (Published 2026-07-21)
  • GHSA-68g3-v927-f742 — Cache confusion of response bodies for requests with bodies (Published 2026-07-21)
  • GHSA-955p-x3mx-jcvp — Unauthenticated disclosure of internal Server Function endpoints (Published 2026-07-21)
  • GHSA-q8wf-6r8g-63ch — Denial of Service in the Image Optimization API using SVGs (Published 2026-07-21)

Components changed

CycloneDX component delta (declared materials — the package's own version, not a dependency-tree diff)
Component Old New
~ next 16.2.6 16.2.11
~ next-upstream 16.2.6 16.2.11

Changes

Old New
Version 16.2.6 16.2.11
SHA256 119c7afb3f19bf3d... 6d6852100501dff3...
Size 50.3 MB
Source https://github.com/vercel/next.js/archive/refs/tags/v16.2.6.tar.gz https://github.com/vercel/next.js/archive/refs/tags/v16.2.11.tar.gz
  • License: MIT (source: GitHub + tarball)

Created by pkgmgr

@twitchyliquid64
twitchyliquid64 added this pull request to the merge queue Jul 22, 2026
Merged via the queue into main with commit b043aad Jul 22, 2026
9 checks passed
@twitchyliquid64
twitchyliquid64 deleted the update-next-16.2.11 branch July 22, 2026 16:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant