Next.js July 2026 Security Release
By BIOS Founding Team

Patched eight CVEs across the two supported LTS lines, the two highest-severity being a Denial-of-Service in the App Router via Server Actions, and a middleware/proxy bypass affecting Turbopack builds with a single configured locale, which could let requests skip authentication checks entirely.
Other fixes addressed SSRF via attacker-controlled rewrite and redirect hostnames, and cache-confusion bugs that could leak one user's fetch response body to another.
Full details: https://nextjs.org/blog/july-2026-security-release
More from the community

Stable and Longterm Kernel Updates: 7.2.4, 6.18.50, 6.12.109
Greg Kroah-Hartman pushed out new stable and longterm point releases across the 7.2, 6.18, and 6.12 lines, each bundling accumulated fixes across drivers, filesystems, and core subsystems.

Rust Debugging Survey 2026 Results
The Rust Project published results from its 2026 debugging survey, gathering community feedback on debugging tools and workflows to guide future tooling investment.

Docker Desktop 4.90.0
This release made 'Ask Gordon,' Docker's AI assistant, accessible as a persistent right-side drawer and added one-click AI diagnosis for containers, images, and volumes with detected issues.