← Back to Resources
Open Source NewsJuly 20, 20262 min read

Next.js July 2026 Security Release

By BIOS Founding Team

Next.js July 2026 Security Release

Patched eight CVEs across the two supported LTS lines, the two highest-severity being a Denial-of-Service in the App Router via Server Actions, and a middleware/proxy bypass affecting Turbopack builds with a single configured locale, which could let requests skip authentication checks entirely.

Other fixes addressed SSRF via attacker-controlled rewrite and redirect hostnames, and cache-confusion bugs that could leak one user's fetch response body to another.

Full details: https://nextjs.org/blog/july-2026-security-release