[Snyk] Upgrade next from 16.2.10 to 16.2.11 - #2686
Conversation
Snyk has created this PR to upgrade next from 16.2.10 to 16.2.11. See this package in npm: next See this project in Snyk: https://app.snyk.io/org/instructure/project/0b0d106a-e39a-450e-b2b1-7f66819e4808?utm_source=github&utm_medium=referral&page=upgrade-pr
|
This is a patch version upgrade from As a patch release focused on security, it is not expected to contain breaking API changes. The changelog for the preceding version, Recommendation: Given this is a security release, upgrading is recommended. No breaking changes are anticipated.
|
|
|
|
|
closing in favor of #2691 |
…lato Applies the four dependency bumps Snyk opened as #2681, #2684, #2685 and #2686: next 16.2.10 -> 16.2.11 react 19.2.7 -> 19.2.8 react-dom 19.2.7 -> 19.2.8 @fontsource/lato ^5.2.7 -> ^5.3.0 The Snyk PRs bumped regression-test/package.json without regenerating the lockfile. This app is outside the pnpm workspace and uses npm, so the visual-regression workflow installs it with `npm ci`, which hard-fails when package.json and package-lock.json disagree. Every one of those PRs therefore died on the "Install regression-test dependencies" step. Regenerated regression-test/package-lock.json alongside the manifest so `npm ci` resolves again. The remaining lockfile churn is npm re-nesting @tailwindcss/oxide-wasm32-wasi's bundled deps rather than hoisting them; no packages were added or dropped. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
Snyk has created this PR to upgrade next from 16.2.10 to 16.2.11.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 1 version ahead of your current version.
The recommended version was released 21 days ago.
Issues fixed by the recommended upgrade:
SNYK-JS-SHARP-18184259
SNYK-JS-SHARP-18184418
SNYK-JS-NEXT-18233133
SNYK-JS-NEXT-18233136
SNYK-JS-NEXT-18233752
SNYK-JS-NANOID-18506897
SNYK-JS-NANOID-18506894
SNYK-JS-SHARP-18184262
SNYK-JS-SHARP-18184416
SNYK-JS-NEXT-18230947
SNYK-JS-NEXT-18233146
SNYK-JS-NEXT-18232299
SNYK-JS-NEXT-18233109
SNYK-JS-NEXT-18231604
Breaking Change Risk
Release notes
Package name: next
-
16.2.11 - 2026-07-21
- Denial of Service in App Router using Server Actions
- Middleware / Proxy bypass in App Router applications using Turbopack and single locale
- Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
- Server-Side Request Forgery in Server Actions on custom servers
- Cache confusion of response bodies for requests with bodies
- Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
- Denial of Service in the Image Optimization API using SVGs
- Unauthenticated disclosure of internal Server Function endpoints
- Unbounded Server Action payload in Edge runtime
-
16.2.10 - 2026-07-01
from next GitHub release notesThis release contains security fixes for the following advisories:
High:
Moderate:
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: