Skip to content

[GHSA-9qr9-h5gf-34mp] Next.js is vulnerable to RCE in React flight protocol#7177

Closed
simonsigre wants to merge 1 commit intosimonsigre/advisory-improvement-7177from
simonsigre-GHSA-9qr9-h5gf-34mp
Closed

[GHSA-9qr9-h5gf-34mp] Next.js is vulnerable to RCE in React flight protocol#7177
simonsigre wants to merge 1 commit intosimonsigre/advisory-improvement-7177from
simonsigre-GHSA-9qr9-h5gf-34mp

Conversation

@simonsigre
Copy link
Copy Markdown

Updates

  • References

Comments
Attempting to bump the advisory to try and get the CVE ID to sync over (unsure of process). The linked Advisory here GHSA-9qr9-h5gf-34mp

@github-actions github-actions bot changed the base branch from main to simonsigre/advisory-improvement-7177 March 15, 2026 20:58
@shelbyc
Copy link
Copy Markdown
Contributor

shelbyc commented Mar 16, 2026

Hi @simonsigre, my colleagues and I have received several requests to link CVE-2025-55182 to GHSA-9qr9-h5gf-34mp in the GHAD. However, per my comment at #6496 (comment), we can't do so because a CVE ID can only be linked to one GHSA ID at a time, and in this case, CVE-2025-55182 is linked to GHSA-fv66-9v8q-g76r.

@shelbyc shelbyc closed this Mar 16, 2026
@github-actions github-actions bot deleted the simonsigre-GHSA-9qr9-h5gf-34mp branch March 16, 2026 12:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants