16.1.7
14 years ago
1 days ago
Known vulnerabilities in the next package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
next is a react framework. Affected versions of this package are vulnerable to Missing Origin Validation in WebSockets in the internal dev endpoint when the How to fix Missing Origin Validation in WebSockets? Upgrade | >=16.0.1 <16.1.7>=16.2.0-canary.0 <16.2.0-canary.102 |
next is a react framework. Affected versions of this package are vulnerable to HTTP Request Smuggling during the rewrite of the proxy traffic to an external backend. An attacker can access unintended backend routes by sending crafted How to fix HTTP Request Smuggling? Upgrade | >=9.5.0 <15.5.13>=16.0.0-beta.0 <16.1.7>=16.2.0-canary.0 <16.2.0-canary.102 |
next is a react framework. Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) due to the uncaught How to fix Cross-site Request Forgery (CSRF)? Upgrade | >=16.0.1 <16.1.7>=16.2.0-canary.0 <16.2.0-canary.102 |