Skip to content

Conversation

@ivanjoe
Copy link

@ivanjoe ivanjoe commented Jan 29, 2026

Updates

  • Affected products

Comments
According to the references below, the versions 15.5.10, 15.5.11, 15.6.0-canary.61 contain the patch agains the vulnerabilities.
https://nvd.nist.gov/vuln/detail/CVE-2025-59472
https://vercel.com/changelog/summaries-of-cve-2025-59471-and-cve-2025-59472

@github
Copy link
Collaborator

github commented Jan 29, 2026

Hi there @andresriancho! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions github-actions bot changed the base branch from main to ivanjoe/advisory-improvement-6741 January 29, 2026 10:33
@cylewaitforit
Copy link

cylewaitforit commented Jan 29, 2026

15.5.10 is still not a resolution for this but 15.5.11 is.

I closed #6742 thinking it was a duplicate of this but I believe it is probably the more accurate update.

@icyJoseph
Copy link

CVE-2025-59472 only affects applications running with the experimental.ppr: true or cacheComponents: true configuration options and NEXT_PRIVATE_MINIMAL_MODE=1 as an environment variable.

Vulnerability to CVE-2025-59472 in v15 apps only happens in 15-canary.x versions - experimental.ppr was only available in the canaries for v15

@helixplant
Copy link

Hi,
We understand the confusion around the version ranges for CVE-2025-59472.
After discussing with the Next.js team, we can confirm that CVE-2025-59472 is patched in versions 15.6.0-canary.61 and 16.1.5. The advisory currently reflects the correct patched versions.
For additional reference, CVE-2025-59471 is patched in versions 15.5.10 and 16.1.5.
Please let us know if you have any other questions.

#6736
#6740
#6745
#6742

@helixplant helixplant closed this Jan 30, 2026
@github-actions github-actions bot deleted the ivanjoe-GHSA-5f7q-jpqc-wp7h branch January 30, 2026 17:06
@cylewaitforit
Copy link

@helixplant Please re-review v15.5.11 as it was released later and states that it backports fixes from v15.6.0-canary.61.

@ztanner
Copy link

ztanner commented Jan 31, 2026

@cylewaitforit 👋 Next.js maintainer here!

v15.5.11 does not contain any security fixes, it was just a regular release for important bugfixes.

PPR on stable versions of v15 would throw an error if you attempted to use it as it was only intended for our pre-release (canary) channel. Hence we did not backport that fix to a v15 release.

@cylewaitforit
Copy link

Thanks @ztanner that is helpful context and if the stable versions were never vulnerable to this then it would confirm that the current versions in this advisory still need adjusting.

As it stands at the moment if a repo is on v15.5.11 or v15.5.10 or any of the other previous stable versions in 15 they would be seeing this advisory, as I am seeing it on v15.5.10. That is because semantically they are all lower than 15.6.0-canary.61 which is currently the lowest listed patched version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants