Skip to content

fix(security): bump marketplace-web next 14.2.21 → 14.2.35 [Critical + High]#1

Open
marcusgear-devgru wants to merge 1 commit intomainfrom
security/marketplace-web-next-14.2.35
Open

fix(security): bump marketplace-web next 14.2.21 → 14.2.35 [Critical + High]#1
marcusgear-devgru wants to merge 1 commit intomainfrom
security/marketplace-web-next-14.2.35

Conversation

@marcusgear-devgru
Copy link
Copy Markdown
Contributor

Security Fix — Dependabot Alerts

Addresses

Alert Severity CVSS Description
#1 CRITICAL 9.1 Authorization Bypass in Next.js Middleware
#7 HIGH 7.5 Next.js Denial of Service with Server Components
#8 HIGH 7.5 Next.js DoS with Server Components (Incomplete Fix Follow-Up)

Change

  • marketplace-web next: 14.2.2114.2.35
  • Lockfile regenerated

Why 14.x (not 15.x)?

Alert #10 (RSC DoS, HIGH) requires upgrading to Next 15. That is a breaking API migration tracked separately. This PR gets us from a critically-vulnerable version to the latest stable 14.x patch.

Verification

npm install --package-lock-only completed without errors. Lockfile shows next@14.2.35.

Refs: TICKET-20260325-DTP-DEPENDABOT-VULN-AUDIT

Fixes Dependabot alerts:
- #1 CRITICAL (CVSS 9.1): Authorization Bypass in Next.js Middleware
- #7 HIGH (CVSS 7.5): Next.js Denial of Service with Server Components
- #8 HIGH (CVSS 7.5): Next.js DoS with Server Components (incomplete fix)

Keeping 14.x (not migrating to 15.x) — marketplace-web has Next 14 API
dependencies and RSC DoS (#10) requires a major version migration that is
tracked separately for product stability.

Refs: Dependabot alerts #1, #7, #8
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant