Skip to content

chore(deps): bump next to 16.2.6 and react to 19.2.6 for May 2026 security fixes - #1

Merged
RobbyV2 merged 1 commit into
mainfrom
claude/check-nextjs-cve-4GmlG
May 14, 2026
Merged

chore(deps): bump next to 16.2.6 and react to 19.2.6 for May 2026 security fixes#1
RobbyV2 merged 1 commit into
mainfrom
claude/check-nextjs-cve-4GmlG

Conversation

@RobbyV2

@RobbyV2 RobbyV2 commented May 14, 2026

Copy link
Copy Markdown
Owner

Patches the Next.js May 2026 coordinated security release (12 advisories
including SSRF via WebSocket upgrades, middleware/proxy bypass, XSS,
cache poisoning, DoS) plus the upstream React Server Components issue
(CVE-2026-23870). Next.js 16.x <= 16.2.5 and React 19.2.x <= 19.2.5 were
affected.

…urity fixes

Patches the Next.js May 2026 coordinated security release (12 advisories
including SSRF via WebSocket upgrades, middleware/proxy bypass, XSS,
cache poisoning, DoS) plus the upstream React Server Components issue
(CVE-2026-23870). Next.js 16.x <= 16.2.5 and React 19.2.x <= 19.2.5 were
affected.
@gitnotebooks

gitnotebooks Bot commented May 14, 2026

Copy link
Copy Markdown

Review these changes at https://app.gitnotebooks.com/RobbyV2/caldav-ics-sync/pull/1

@RobbyV2
RobbyV2 merged commit a7ce415 into main May 14, 2026
2 checks passed
@RobbyV2
RobbyV2 deleted the claude/check-nextjs-cve-4GmlG branch July 31, 2026 23:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants