The React Framework
Published Node.js and peer-dependency requirements.
No declared requirement changes.
11 Aug 2021 · Newest first
Last checked
Checking sources…
Showing 1 of 1 releases. Full release notes.
Signals highlight changes worth reviewing. They cannot determine whether your application is affected.
We've landed a patch that ensures path parsing is handled properly for these paths so that the open redirect can no longer occur.
A security team from one of our partners noticed an issue in Next.js that allowed for an open redirect to occur.
Specially encoded paths could be used when pages/_error.js was statically generated allowing an open redirect to occur to an external site.
In general, this redirect does not directly harm users although can allow for phishing attacks by redirecting to an attacker's domain from a trusted domain.
We recommend upgrading to the latest version of Next.js to improve the overall security of your application.
npm install next@latest --savepages/_error.js without getInitialPropspages/_error.js and next exportpages/404.jsWe recommend everyone to upgrade regardless of whether you can reproduce the issue or not.
If you think sensitive code or data could have been exposed, you can filter logs of affected sites by // (double slash at the start of the url) followed by a domain.
As Next.js has grown in popularity and usage by enterprises, it has received the attention of security researchers and auditors. We are thankful to Gabriel Benmergui from Robinhood for their investigation and discovery of the original bug and subsequent responsible disclosure.
We've landed a patch that ensures path parsing is handled properly for these paths so that the open redirect can no longer occur.
Regression tests for this attack were added to the security integration test suite
security@vercel.com. We are actively monitoring this mailbox.next lint: #26697next-dev-server implementation: #26230max-age to optimized image: #26739lunix → linux: #26796package.json: #27121publish-canary script to include checkout: #26840create-next-app next-env.d.ts: #26890placeholder=blur with assetPrefix: #27120Huge thanks to @atcastle, @vitalybaev, @leerob, @destruc7i0n, @styfle, @petermekhaeil, @phocks, @pranavp10, @huozhi, @ijjk, @johnrackles, @timneutkens, @Vadorequest, @hiro0218, @housseindjirdeh, @sohamsshah, @devknoll, @schoenwaldnils, @kasipavankumar, @jviide, @sedlukha, @PaulvdDool, @padmaia, @LetItRock, @angeloashmore, @sachinraja, @pa-rang, @theostrahlen, @schultzp2020, @lsndr, @sokra, @andys-github, @darshkpatel, @tanys123, @papaponmx, @karlsander, @borekb, @michielvangendt, @rishabhpoddar, @enesakar, @ctbarna, @markkaylor, @stovmascript, @lucleray, @mvasilkov, @nyedidikeke, @mastoj, @janicklas-ralph, @ThangHuuVu, @Munawwar, @reod, @thomasmarshall, @AndreVarandas, @Ryz0nd, @qwertyforce, @samrobbins85, @brandonchinn178, @adam-cowley, @akellbl4, @jflayhart, @jaybekster, @stuymedova, @m-abdelwahab, @UniqueNL, @jamsinclair, @fabb, @abotsi, @kylemh, @JacobLey, @AryanBeezadhur, @afbarbaro, @javivelasco, @breyed, @roim, @mandarons, @stefanprobst, @sa3dany, @jarvelov, @apuyou, @gnbaron, @kaykdm, @michalbundyra, @brijendravarma, @tmcgann, @arturmuller, @noahweingand, @omasher, @yunger7, @raon0211, @noreiller, @shibe23, @enzoferey, @JeffersonBledsoe, @Timvdv, @smitssjors, @zackdotcomputer, @jameshoward, @tigger9flow, @sergioalvz, @tomchen, @kdy1, @zeekrey, @NickKelly1, @orta, @euess, @NickCrews, @ctjlewis, @delbaoliveira, @ahmedosama7450, @samsisle, and @mrmckeb for helping!
onLoadingComplete() prop to Image component: #26824.eslintrc file created to have .json format: #26884ResponsePayload support: #26938IncrementalCache API: #26941respondWith: #26961next/script interface Props to ScriptProps: #26990next/image TS types for width and height: #26991dangerously-unoptimized loader for next/image: #26847next/image TS types for src: #26996dangerously-unoptimized to custom and warn when applicable: #26998next-env.d.ts: #27028next dev performance with placeholder=blur: #27061web-vitals to v1.1.2.: #25272withCoalescedInvoke with ResponseCache: #26997minimumCacheTTL config for Image Optimization: #27200next/script component: #27218minimumCacheTTL so it doesn't affect browser caching: #27307placeholder=blur inside <noscript>: #27311RequestContext: #27303keepAlive to node-fetch polyfill: #27376null responses: #27403lazyBoundary prop to Image component: #27258NextConfig type: #27446next/image component has style prop: #27441--format flag to next lint: #27052RenderResult: #27319onLoadingComplete() callback: #27695next.config.js option to override default keepAlive: #27709removeHeader() function to image optimizer mock res: #27763next lint is run for the first time: #26584else to fix tree shaking: #27788placeholder with blurDataURL in global StaticImageData type: #27916next/script unhandled promise rejection: #27903concurrentFeatures config: #27768next build when sharp is missing: #27933no-duplicate-head rule: #27179next/image docs with onLoadingComplete(): #27440next/script must not be in next/head: #27534hrefas prop from <Link> components: #27359util to lib in with-mongodb example: #27404utils to lib in with-mongodb-mongoose example: #27407next/script to pages/_app in script loader integration tests: #27626next build when sharp is missing (#27933)"