Dependency update tracking
Date: 2026-09-09
Branch: chore/deps-update-202609091032
Prerelease tag: skipped
Node.js: 24.x
pnpm: 10.x
This issue tracks the automated dependency update. It will be closed automatically when the linked PR is merged.
Dependency update results
- Check: success
- Build: success
- Test: success
Semver bump log
Audit log
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ critical │ Next.js: Unauthenticated Remote Code Execution on │
│ │ windows-hosted servers │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.4.0 <15.5.24 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=15.5.24 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-p293-qw3h-jr36 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ critical │ Next.js: Unauthenticated Remote Code Execution in │
│ │ Image Optimization API when AVIF files are used │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=10.0.0 <15.5.24 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=15.5.24 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-2xp9-vwfh-vxw4 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js Server-Side Request Forgery in Server Actions │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.4.0 <14.1.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=14.1.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-fr5h-rqp8-mj6g │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Server-Side Request Forgery in axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.3.2 <=1.7.3 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.7.4 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-8hc4-vh64-cxmj │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js authorization bypass vulnerability │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=9.5.5 <14.2.15 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=14.2.15 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-7gfc-8cq8-jh5f │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ axios Requests Vulnerable To Possible SSRF and │
│ │ Credential Leakage via Absolute URL │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <0.30.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=0.30.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-jr5f-v2jv-69x6 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ axios Requests Vulnerable To Possible SSRF and │
│ │ Credential Leakage via Absolute URL │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.8.2 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.8.2 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-jr5f-v2jv-69x6 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next Vulnerable to Denial of Service with Server │
│ │ Components │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.3.0 <14.2.34 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=14.2.34 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-mwv6-3258-q52c │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next has a Denial of Service with Server Components - │
│ │ Incomplete Fix Follow-Up │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.3.1-canary.0 <14.2.35 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=14.2.35 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-5j59-xgg2-r9c4 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios is vulnerable to DoS attack through lack of data │
│ │ size check │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.12.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.12.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4hjh-wcwx-xvwj │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js HTTP request deserialization can lead to DoS │
│ │ when using insecure React Server Components │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.0.0 <15.0.8 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=15.0.8 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-h25m-26qc-wcjf │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ minimatch has a ReDoS via repeated wildcards with │
│ │ non-matching literal in pattern │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=9.0.0 <9.0.6 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=9.0.6 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>eslint-config-next>@typescript-eslint/ │
│ │ parser>@typescript-eslint/typescript-estree>minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-3ppc-4f35-3m26 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ minimatch has ReDoS: matchOne() combinatorial │
│ │ backtracking via multiple non-adjacent GLOBSTAR │
│ │ segments │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=9.0.0 <9.0.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=9.0.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>eslint-config-next>@typescript-eslint/ │
│ │ parser>@typescript-eslint/typescript-estree>minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-7r86-cg39-jmmj │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ minimatch ReDoS: nested *() extglobs generate │
│ │ catastrophically backtracking regular expressions │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=9.0.0 <9.0.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=9.0.7 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>eslint-config-next>@typescript-eslint/ │
│ │ parser>@typescript-eslint/typescript-estree>minimatch │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-23c5-xmqv-rm74 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js has a Denial of Service with Server Components │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.0.0 <15.5.15 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=15.5.15 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-q4gf-8mx6-v5v3 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY │
│ │ Protection Bypassed via RFC 1122 Loopback Subnet │
│ │ (127.0.0.0/8) in Axios 1.15.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.31.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=0.31.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-pmwg-cvhr-8vh7 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY │
│ │ Protection Bypassed via RFC 1122 Loopback Subnet │
│ │ (127.0.0.0/8) in Axios 1.15.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.15.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.15.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-pmwg-cvhr-8vh7 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios: Prototype Pollution Gadgets - Response │
│ │ Tampering, Data Exfiltration, and Request Hijacking │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.31.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=0.31.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-pf86-5x62-jrwf │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios: Prototype Pollution Gadgets - Response │
│ │ Tampering, Data Exfiltration, and Request Hijacking │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.15.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.15.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-pf86-5x62-jrwf │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios: Header Injection via Prototype Pollution │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.31.0 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=0.31.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-6chq-wfr3-2hj9 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios: Header Injection via Prototype Pollution │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.15.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.15.1 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-6chq-wfr3-2hj9 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios is Vulnerable to Denial of Service via __proto__ │
│ │ Key in mergeConfig │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=0.30.2 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=0.30.3 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-43fc-jf86-j433 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios is Vulnerable to Denial of Service via __proto__ │
│ │ Key in mergeConfig │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <=1.13.4 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.13.5 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-43fc-jf86-j433 │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js Vulnerable to Denial of Service with Server │
│ │ Components │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.0.0 <15.5.16 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=15.5.16 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-8h8q-6873-q5fj │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Axios has prototype pollution read-side gadgets in │
│ │ HTTP adapter that allow credential injection and │
│ │ request hijacking │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=1.0.0 <1.15.2 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=1.15.2 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>@commercelayer/react-components>@commercelayer/ │
│ │ sdk>axios │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-q8qp-cvcw-x6jj │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js vulnerable to server-side request forgery in │
│ │ applications using WebSocket upgrades │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=13.4.13 <15.5.16 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=15.5.16 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-c4j6-fc7j-m34r │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high │ Next.js has a Middleware / Proxy bypass in Pages │
│ │ Router applications using i18n │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package │ next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=12.2.0 <15.5.16 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions │ >=15.5.16 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths │ .>next │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-36qx-fr4f-26g5 │
└───────
...truncated...
Dependency update tracking
Date:
2026-09-09Branch:
chore/deps-update-202609091032Prerelease tag:
skippedNode.js:
24.xpnpm:
10.xThis issue tracks the automated dependency update. It will be closed automatically when the linked PR is merged.
Dependency update results
Semver bump log
Audit log