Blog

Insights on software development, security, and technology from our team.

Showing posts taggedtech-news

A Next.js OG-image bug can run code on your server. Patch to 16.3.6.

Vercel shipped an out-of-band Next.js update on September 22 to fix CVE-2026-94545, a critical remote code execution bug in the Node.js `ImageResponse` from `next/og`, scored CVSS 9.5. It only bites apps that feed visitor-controlled values into dynamic Open Graph images, but that describes most share-card setups. Here is who is exposed, why patching the framework alone may not be enough, and what to check today.

Shopify is leaving React Native for Swift and Kotlin. The reason isn't what you think.

Shopify is rebuilding its mobile apps in Swift and Kotlin, not because React Native was slow, but because AI agents changed the cost of two codebases. Here's what mobile teams should actually take from it, and the headless-logic trick that works whatever stack you're on.

React 19.3 makes View Transitions stable. Turn on Trusted Types while you're there.

React 19.3 shipped on September 9, 2026, promoting View Transitions and Fragment Refs to stable and adding Trusted Types support and a use(browser()) escape hatch. Here's what web, security, and mobile teams should actually do with it.

A PostgreSQL backup account can now run code on your server. Patch CVE-2026-6471.

PostgreSQL patched CVE-2026-6471, a flaw present since 2014 that lets a low-privilege REPLICATION account load arbitrary code and take over the database host. The official severity is 7.2, not critical, because it needs an account that backup tools, replicas and CDC pipelines all use. Here is how to patch, what the new output_plugin_libraries allowlist changes, and which service accounts to audit first.

React Native 0.87 makes the Strict TypeScript API the default. Here's your upgrade order.

React Native 0.87 landed on August 11, and it makes the Strict TypeScript API the default for every project. That turns deep imports into type errors and reshapes ref types, on top of experimental Swift Package Manager support, AGP 9, and a higher toolchain floor. Here is the upgrade order we would actually use, and the one grep that tells you how much work you are in for.

SQLite carried a corruption bug for 16 years. Here's why yours is probably fine, and what to check anyway.

Tailscale spent six months chasing database corruption that turned out to be a 16-year-old data race in SQLite's WAL mode. The fix landed in SQLite 3.51.3, but the real work for most teams is finding out which SQLite version they actually run and proving their backups restore clean. Here's what we'd do about it.

A polluted prototype can hijack your axios traffic. Upgrade to 1.18.0.

axios just disclosed CVE-2026-67320, a prototype pollution flaw in its Node.js HTTP adapter that can reroute your server's outbound requests through an attacker-controlled proxy and leak credentials over plaintext HTTP. It's a sharp reminder that a dependency you barely configure is still attack surface. Here's what to patch, and what to change beyond the patch.

React Compiler goes Rust, and Next.js 16.3 can already use it

The React team rewrote the React Compiler in Rust, and Vercel wired it into Turbopack. Next.js 16.3 reports 20 to 50% faster route compilation on the native path. We break down whether the experimental flag is worth flipping, and how to test it without risking production.

One POST request now owns a default WordPress site. Patch to 7.0.2 today.

WordPress just patched wp2shell, an unauthenticated remote-code-execution chain in core that turns one crafted request into a full site takeover on a default install. It affects versions 6.8 through 7.0.1, and public exploit code is already circulating. Here's what web and security teams should do this week, and how to check if you were already hit.

SwiftUI's @State just became a macro, and Xcode 27 will break some of your builds

WWDC 2026 turned SwiftUI's @State from a property wrapper into a macro. In Xcode 27 a common init pattern now fails to compile. The App Store floor is still iOS 26, so this is a chore you can schedule, not an emergency, if you start now.

A critical PhpSpreadsheet bug walked straight through its own patch

PhpSpreadsheet's fix for a phar deserialization bug got bypassed with a path carrying one extra slash. The new flaw, CVE-2026-45034, is a 9.2 critical: full remote code execution on PHP 7.x and a file-read primitive on PHP 8.x. Here is how the bypass works and what your team should do this week.

TypeScript 7.0 is 10x faster and written in Go. Here's how to adopt it without breaking CI.

Microsoft shipped the TypeScript 7.0 Release Candidate on June 18, 2026, and the big change is the compiler itself, now written in Go and roughly 10x faster than 6.0. It's a port rather than a rewrite, so the type rules stay the same. The smart move is to run it as a shadow CI job now and adopt it on your own schedule.