
Yeah it’s over for NextJS... 13 NEW vulnerabilities
Source: YouTube · Better Stack · published May 11, 2026 · 15:55
BLUF: A recent security release for React and Next.js addresses 13 vulnerabilities, including six high-severity issues like denial of service and cross-site scripting, urging immediate upgrades 0:09.
Key Takeaways:
• The release contains 13 CVEs across React and Next.js, with six classified as high severity 0:09.
• Critical risks include denial of service, middleware bypasses, and cross-site scripting attacks 0:14.
• Users are advised to upgrade their Next.js versions to resolve these vulnerabilities 0:30.
• TanStack is explicitly noted as not being impacted by these specific security issues 0:36.
The speaker suggests that the frequency of such security issues in server components might lead some to question their viability, while also highlighting TanStack as a secure alternative 0:18.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Ah, it happened again. This is like my third video on server component CVS this year and I don't even think I covered all of them. This time it's 13 CVS. Yes, 13 of them across React and Next.js. Six of which are high severity and include denial of service, middleware bypasses, cross-sight scripting, and more. Maybe server components were a mistake. So, here's the next year security release. you know, just fixing a few casual issues in here that they've had this month. And down at the bottom, obviously, the resolution is to upgrade all of your nextgs versions, and these are the impacted versions. It's worth noting Tanstack is not impacted by this, which I might be biased, but that's another reason to use Tanstack for me. Now, I won't go through all of these as we'd probably be here for a w…