This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Netlify
netlify.com
did:plc:2r34nn3vhizjhrywajc4jjnn
Nine new Next.js CVEs: SSRF, a middleware auth bypass, DoS, and cache confusion. Fixed in 15.5.21 and 16.2.11.
Good news for Netlify users: three of them don't affect Netlify-hosted sites at all. The per-issue breakdown, plus what to do now: https://www.netlify.com/changelog/2026-07-21-nextjs-security-vulnerabilities/
2026-07-21T17:21:52.180Z