News
Two Next.js Vulnerabilities Disclosed in the August 2026 Security Release
Vercel published a changelog entry confirming two vulnerabilities affecting Next.js were disclosed in the August 2026 Security Release, and that Next.js applications hosted on Vercel are protected with no customer action required. Self-hosted Next.js deployments are the exposure here and need the patched release applied directly. Anyone running Next.js outside Vercel should treat the 'protected, no action needed' framing as scoped to Vercel-hosted apps only.
↳ Follow the thread