') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); fix: upgrade next to 16.2.11 to address CVE-2026-64641 by TooTallNate · Pull Request #3071 · vercel/workflow · GitHub
Skip to content

fix: upgrade next to 16.2.11 to address CVE-2026-64641 - #3071

Merged
TooTallNate merged 1 commit into
mainfrom
naterajlich/vuln-13454-dependency-vulnerability-cve-2026-64641-affects-next1621-in
Jul 23, 2026
Merged

fix: upgrade next to 16.2.11 to address CVE-2026-64641#3071
TooTallNate merged 1 commit into
mainfrom
naterajlich/vuln-13454-dependency-vulnerability-cve-2026-64641-affects-next1621-in

Conversation

@TooTallNate

Copy link
Copy Markdown
Member

Fixes VULN-13454

Summary

Socket.dev flagged next@16.2.1 (CVE-2026-64641, CVSS 8.2 High) — DoS via crafted requests to App Router apps using Server Actions. Affected versions: >= 13.0.0 < 15.5.21; >= 16.0.0 < 16.2.11.

Changes

Bumped next to 16.2.11 everywhere a vulnerable version was declared:

  • workbench/swc-playground: 16.2.116.2.11 (the manifest the alert was filed against)
  • docs: 16.2.616.2.11
  • workbench/nextjs-turbopack / workbench/nextjs-webpack: 16.2.1016.2.11
  • packages/next (devDependency): 16.2.1016.2.11 — peer range (>13) unchanged
  • Lockfile now resolves a single next@16.2.11 (previous 16.2.1 / 16.2.6 / 16.2.10 entries removed)

postcss override (CVE-2026-45623) — kept

Checked whether the postcss@<8.5.12: 8.5.16 override from #3067 could be removed: it cannot. next@16.2.11 still declares postcss: 8.4.31 upstream, which is inside that CVE's affected range, so the override remains and continues to map it to 8.5.16 (verified in the lockfile).

Verification

  • Fresh pnpm install + pnpm build (27/27 tasks) pass
  • workbench/nextjs-turbopack production build succeeds on next@16.2.11
  • Changeset included for @workflow/next (patch); pnpm changeset status --since=main passes

CopilotAI review requested due to automatic review settings July 23, 2026 22:02
@TooTallNate
TooTallNate requested review from a team and ijjk as code ownersJuly 23, 2026 22:02
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: c7fdb39

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 16 packages
NameType
@workflow/nextPatch
workflowPatch
@workflow/world-testingPatch
@workflow/corePatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/nuxtPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions

github-actionsBot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

All tests passed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production145502391694
✅ 💻 Local Development162102271848
✅ 📦 Local Production162102271848
✅ 🐘 Local Postgres162102271848
✅ 🪟 Windows15400154
✅ 📋 Other102002121232
✅ vercel-multi-region270027
Total7519011328651

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro126028
✅ example126028
✅ express126028
✅ fastify126028
✅ hono126028
✅ nextjs-turbopack15103
✅ nextjs-webpack15103
✅ nitro126028
✅ nuxt126028
✅ sveltekit14509
✅ vite126028
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable128026
✅ express-stable128026
✅ fastify-stable128026
✅ hono-stable128026
✅ nextjs-turbopack-canary135019
✅ nextjs-turbopack-stable15400
✅ nextjs-webpack-canary135019
✅ nextjs-webpack-stable15400
✅ nitro-stable128026
✅ nuxt-stable128026
✅ sveltekit-stable14707
✅ vite-stable128026
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable128026
✅ express-stable128026
✅ fastify-stable128026
✅ hono-stable128026
✅ nextjs-turbopack-canary135019
✅ nextjs-turbopack-stable15400
✅ nextjs-webpack-canary135019
✅ nextjs-webpack-stable15400
✅ nitro-stable128026
✅ nuxt-stable128026
✅ sveltekit-stable14707
✅ vite-stable128026
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable128026
✅ express-stable128026
✅ fastify-stable128026
✅ hono-stable128026
✅ nextjs-turbopack-canary135019
✅ nextjs-turbopack-stable15400
✅ nextjs-webpack-canary135019
✅ nextjs-webpack-stable15400
✅ nitro-stable128026
✅ nuxt-stable128026
✅ sveltekit-stable14707
✅ vite-stable128026
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack15400
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable128026
✅ e2e-local-dev-tanstack-start-128026
✅ e2e-local-postgres-nest-stable128026
✅ e2e-local-postgres-tanstack-start-128026
✅ e2e-local-prod-nest-stable128026
✅ e2e-local-prod-tanstack-start-128026
✅ e2e-vercel-prod-nest126028
✅ e2e-vercel-prod-tanstack-start126028
✅ vercel-multi-region
AppPassedFailedSkipped
✅ nextjs-turbopack2700

📋 View full workflow run

@vercel

vercelBot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actionsBot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

📊 Workflow Benchmarks

commit c7fdb39 · Thu, 23 Jul 2026 22:16:31 GMT · run logs

Backend: vercel · app: nextjs-turbopack

MetricScenarioBest (ms)P75 (ms)P90 (ms)P99 (ms)Samples
TTFSstep1108 (+338%) 🔻1176 🔴 (+9.9%)1183 🔴 (+4.8%)1199 🔴 (-21%) 💚30
TTFSstream1112 (+20%) 🔻1162 🔴 (+15%)1184 🔴 (+15%)1519 🔴 (+44%) 🔻30
TTFShook + stream654 (+15%)1412 🔴 (+8.7%)1426 🔴 (+6.7%)1526 🔴 (-8.5%)30
STSO1020 steps (1-20)170 (+4.3%)243 🔴 (-5.8%)296 🔴 (-16%) 💚338 🔴 (-18%) 💚19
STSO1020 steps (101-120)166 (-8.3%)240 🔴 (-9.8%)297 🔴 (-6.6%)480 🔴 (+41%) 🔻19
STSO1020 steps (1001-1020)440 (-5.6%)504 🔴 (-6.1%)559 🔴 (±0%)618 🔴 (-20%) 💚19
WO1020 steps359818 (-7.7%)359818 (-7.7%)359818 (-7.7%)359818 (-7.7%)1
SLstream latency83 (+1.2%)134 🔴 (+21%) 🔻148 🔴 (+14%)170 🔴 (-19%) 💚30

Best/P75/P90/P99 deltas compare against the most recent benchmark run on main at the time of this run. 🔻 flags a delta worse than +15%, 💚 one better than −15%.

Metrics — TTFS: time to first step body (in-deployment start() → first step body, deployment clocks) · STSO: step-to-step overhead (gap between consecutive step bodies) · WO: workflow overhead (whole-run time outside step bodies, in-deployment anchored) · SL: stream latency (in-deployment write → read propagation, readAt - writtenAt)

Scenarios — step: one trivial no-op step, no stream; no hooks, so the run stays in turbo mode (in-process fast path) · stream: one streaming step; no hooks, so the run stays in turbo mode (in-process fast path) · hook + stream: registers a hook before one step, which exits turbo mode (dispatch path) · 1020 steps: 1020 trivial sequential steps; STSO is measured between consecutive steps in the given step ranges, and WO is the whole-run overhead outside step bodies · stream latency: parallel reader/writer steps on a dedicated stream; SL is the in-deployment write->read propagation (readAt - writtenAt)

🔴 marks a percentile over its target (within target is left unmarked). Targets (p75/p90/p99, ms) — TTFS 200/300/600 · SL 50/60/125 · STSO (1-20) 20/30/60 · STSO (101-120) 30/45/90 · STSO (1001-1020) 40/60/120

All metrics are measured from deployment-side timestamps only. Runs are triggered by an in-deployment route that stamps the anchor (clientStart) right before start(), so the CI runner’s request and its path through api.vercel.com sit outside every measured window. TTFS = in-deployment start() → first step body (turbo uses the in-process fast path, non-turbo the dispatch path), and includes the VQS dispatch hop plus any /flow cold start. STSO/WO are measured between step bodies on the deployment. SL is measured inside the workflow (parallel reader/writer steps), so it no longer includes the api.vercel.com read path.

Cold starts are kept in the numbers on purpose — they are part of real bursty-workload latency. The workbench deployment cold-starts the /flow invocation for a large fraction of runs, inflating P75+; the Best column shows the fastest (warm-start) sample for comparison.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Upgrades Next.js to 16.2.11 across the repo to remediate CVE-2026-64641 (DoS affecting App Router + Server Actions), ensuring all declared versions and the lockfile resolve to the patched release.

Changes:

  • Bump next to 16.2.11 in all workbenches/docs that previously pinned vulnerable 16.2.x versions.
  • Update packages/next devDependency to 16.2.11 (peer range unchanged).
  • Regenerate pnpm-lock.yaml to remove older next@16.2.{1,6,10} resolutions and converge on 16.2.11.

Reviewed changes

Copilot reviewed 6 out of 7 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
workbench/swc-playground/package.jsonPins next to 16.2.11 for the swc playground app.
workbench/nextjs-webpack/package.jsonPins next to 16.2.11 for the webpack workbench app.
workbench/nextjs-turbopack/package.jsonPins next to 16.2.11 for the turbopack workbench app.
docs/package.jsonPins next to 16.2.11 for the docs site workspace.
packages/next/package.jsonUpdates next devDependency to 16.2.11 for @workflow/next.
pnpm-lock.yamlRemoves older Next.js resolutions and updates the dependency graph to next@16.2.11.
.changeset/hip-onions-refuse.mdAdds a patch changeset for @workflow/next reflecting the devDependency bump.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@TooTallNate
TooTallNate merged commit f11e9fe into mainJul 23, 2026
103 of 104 checks passed
@TooTallNate
TooTallNate deleted the naterajlich/vuln-13454-dependency-vulnerability-cve-2026-64641-affects-next1621-in branch July 23, 2026 22:18
@github-actionsgithub-actionsBot mentioned this pull request Jul 23, 2026
github-actionsBot added a commit that referenced this pull request Jul 23, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Backport PR opened against stable: #3073. Merge conflicts were resolved by AI — please review carefully. (backport job run)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@TooTallNate@VaguelySerious