From 0d8d7ad824f6329caa221146d4f744caf24aeab8 Mon Sep 17 00:00:00 2001 From: Charly Gomez Date: Thu, 19 Mar 2026 10:01:36 +0100 Subject: [PATCH] fix(deps): bump next to 15.5.13/16.1.7 to fix CVE-2026-1525, CVE-2026-33036 and related MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Fixes Dependabot alerts #1165-#1215 (HTTP smuggling, image disk cache DoS, WebSocket DoS, CSRF null origin bypass in Next.js). - nextjs-16-bun/cacheComponents/cf-workers/trailing-slash/tunnel: 16.1.5 → 16.1.7 - nextjs-sourcemaps: 16.1.6 → 16.1.7 - nextjs-15, nextjs-15-intl: 15.5.10 → 15.5.13 - nextjs-15-t3: ^15.5.9 → ^15.5.13 Co-Authored-By: Claude Sonnet 4.6 --- .../e2e-tests/test-applications/nextjs-15-intl/package.json | 2 +- .../e2e-tests/test-applications/nextjs-15-t3/package.json | 2 +- dev-packages/e2e-tests/test-applications/nextjs-15/package.json | 2 +- .../e2e-tests/test-applications/nextjs-16-bun/package.json | 2 +- .../test-applications/nextjs-16-cacheComponents/package.json | 2 +- .../test-applications/nextjs-16-cf-workers/package.json | 2 +- .../test-applications/nextjs-16-trailing-slash/package.json | 2 +- .../e2e-tests/test-applications/nextjs-16-tunnel/package.json | 2 +- .../e2e-tests/test-applications/nextjs-sourcemaps/package.json | 2 +- 9 files changed, 9 insertions(+), 9 deletions(-) diff --git a/dev-packages/e2e-tests/test-applications/nextjs-15-intl/package.json b/dev-packages/e2e-tests/test-applications/nextjs-15-intl/package.json index 724312c14873..9e18defda67b 100644 --- a/dev-packages/e2e-tests/test-applications/nextjs-15-intl/package.json +++ b/dev-packages/e2e-tests/test-applications/nextjs-15-intl/package.json @@ -15,7 +15,7 @@ "@types/node": "^18.19.1", "@types/react": "18.0.26", "@types/react-dom": "18.0.9", - "next": "15.5.10", + "next": "15.5.13", "next-intl": "^4.3.12", "react": "latest", "react-dom": "latest", diff --git a/dev-packages/e2e-tests/test-applications/nextjs-15-t3/package.json b/dev-packages/e2e-tests/test-applications/nextjs-15-t3/package.json index b3cf747a0866..380e2ce0f66f 100644 --- a/dev-packages/e2e-tests/test-applications/nextjs-15-t3/package.json +++ b/dev-packages/e2e-tests/test-applications/nextjs-15-t3/package.json @@ -20,7 +20,7 @@ "@trpc/client": "~11.8.0", "@trpc/react-query": "~11.8.0", "@trpc/server": "~11.8.0", - "next": "^15.5.9", + "next": "^15.5.13", "react": "^19.1.0", "react-dom": "^19.1.0", "server-only": "^0.0.1", diff --git a/dev-packages/e2e-tests/test-applications/nextjs-15/package.json b/dev-packages/e2e-tests/test-applications/nextjs-15/package.json index 897e5a2ea243..fc876dc41ba7 100644 --- a/dev-packages/e2e-tests/test-applications/nextjs-15/package.json +++ b/dev-packages/e2e-tests/test-applications/nextjs-15/package.json @@ -20,7 +20,7 @@ "@types/react": "18.0.26", "@types/react-dom": "18.0.9", "ai": "^3.0.0", - "next": "15.5.10", + "next": "15.5.13", "react": "latest", "react-dom": "latest", "typescript": "~5.0.0", diff --git a/dev-packages/e2e-tests/test-applications/nextjs-16-bun/package.json b/dev-packages/e2e-tests/test-applications/nextjs-16-bun/package.json index 2540ca74678c..75e51867a38c 100644 --- a/dev-packages/e2e-tests/test-applications/nextjs-16-bun/package.json +++ b/dev-packages/e2e-tests/test-applications/nextjs-16-bun/package.json @@ -15,7 +15,7 @@ "@sentry/nextjs": "latest || *", "@sentry/core": "latest || *", "import-in-the-middle": "^2", - "next": "16.1.5", + "next": "16.1.7", "react": "19.1.0", "react-dom": "19.1.0", "require-in-the-middle": "^8" diff --git a/dev-packages/e2e-tests/test-applications/nextjs-16-cacheComponents/package.json b/dev-packages/e2e-tests/test-applications/nextjs-16-cacheComponents/package.json index 9f9e2481073f..bc306ef7dab7 100644 --- a/dev-packages/e2e-tests/test-applications/nextjs-16-cacheComponents/package.json +++ b/dev-packages/e2e-tests/test-applications/nextjs-16-cacheComponents/package.json @@ -26,7 +26,7 @@ "@sentry/nextjs": "latest || *", "@sentry/core": "latest || *", "import-in-the-middle": "^1", - "next": "16.1.5", + "next": "16.1.7", "react": "19.1.0", "react-dom": "19.1.0", "require-in-the-middle": "^7", diff --git a/dev-packages/e2e-tests/test-applications/nextjs-16-cf-workers/package.json b/dev-packages/e2e-tests/test-applications/nextjs-16-cf-workers/package.json index 7cfd9ee18c99..9695657cbd3f 100644 --- a/dev-packages/e2e-tests/test-applications/nextjs-16-cf-workers/package.json +++ b/dev-packages/e2e-tests/test-applications/nextjs-16-cf-workers/package.json @@ -20,7 +20,7 @@ "@opennextjs/cloudflare": "^1.14.9", "@sentry/nextjs": "latest || *", "@sentry/core": "latest || *", - "next": "16.1.5", + "next": "16.1.7", "react": "19.1.0", "react-dom": "19.1.0" }, diff --git a/dev-packages/e2e-tests/test-applications/nextjs-16-trailing-slash/package.json b/dev-packages/e2e-tests/test-applications/nextjs-16-trailing-slash/package.json index c097fd9e2b98..ea0475e5ed61 100644 --- a/dev-packages/e2e-tests/test-applications/nextjs-16-trailing-slash/package.json +++ b/dev-packages/e2e-tests/test-applications/nextjs-16-trailing-slash/package.json @@ -16,7 +16,7 @@ "@sentry/nextjs": "latest || *", "@sentry/core": "latest || *", "import-in-the-middle": "^2", - "next": "16.1.5", + "next": "16.1.7", "react": "19.1.0", "react-dom": "19.1.0", "require-in-the-middle": "^8" diff --git a/dev-packages/e2e-tests/test-applications/nextjs-16-tunnel/package.json b/dev-packages/e2e-tests/test-applications/nextjs-16-tunnel/package.json index 483f1019f93e..5a1fed010500 100644 --- a/dev-packages/e2e-tests/test-applications/nextjs-16-tunnel/package.json +++ b/dev-packages/e2e-tests/test-applications/nextjs-16-tunnel/package.json @@ -27,7 +27,7 @@ "@sentry/core": "latest || *", "ai": "^3.0.0", "import-in-the-middle": "^1", - "next": "16.1.5", + "next": "16.1.7", "react": "19.1.0", "react-dom": "19.1.0", "require-in-the-middle": "^7", diff --git a/dev-packages/e2e-tests/test-applications/nextjs-sourcemaps/package.json b/dev-packages/e2e-tests/test-applications/nextjs-sourcemaps/package.json index 84bb06365b76..16d2ef6d6050 100644 --- a/dev-packages/e2e-tests/test-applications/nextjs-sourcemaps/package.json +++ b/dev-packages/e2e-tests/test-applications/nextjs-sourcemaps/package.json @@ -10,7 +10,7 @@ }, "dependencies": { "@sentry/nextjs": "latest || *", - "next": "16.1.6", + "next": "16.1.7", "react": "19.1.0", "react-dom": "19.1.0", "typescript": "~5.0.0"