Blog

Insights on software development, security, and technology from our team.

Showing posts taggedvulnerability

A Next.js OG-image bug can run code on your server. Patch to 16.3.6.

Vercel shipped an out-of-band Next.js update on September 22 to fix CVE-2026-94545, a critical remote code execution bug in the Node.js `ImageResponse` from `next/og`, scored CVSS 9.5. It only bites apps that feed visitor-controlled values into dynamic Open Graph images, but that describes most share-card setups. Here is who is exposed, why patching the framework alone may not be enough, and what to check today.

A PostgreSQL backup account can now run code on your server. Patch CVE-2026-6471.

PostgreSQL patched CVE-2026-6471, a flaw present since 2014 that lets a low-privilege REPLICATION account load arbitrary code and take over the database host. The official severity is 7.2, not critical, because it needs an account that backup tools, replicas and CDC pipelines all use. Here is how to patch, what the new output_plugin_libraries allowlist changes, and which service accounts to audit first.

A polluted prototype can hijack your axios traffic. Upgrade to 1.18.0.

axios just disclosed CVE-2026-67320, a prototype pollution flaw in its Node.js HTTP adapter that can reroute your server's outbound requests through an attacker-controlled proxy and leak credentials over plaintext HTTP. It's a sharp reminder that a dependency you barely configure is still attack surface. Here's what to patch, and what to change beyond the patch.

One POST request now owns a default WordPress site. Patch to 7.0.2 today.

WordPress just patched wp2shell, an unauthenticated remote-code-execution chain in core that turns one crafted request into a full site takeover on a default install. It affects versions 6.8 through 7.0.1, and public exploit code is already circulating. Here's what web and security teams should do this week, and how to check if you were already hit.

A critical PhpSpreadsheet bug walked straight through its own patch

PhpSpreadsheet's fix for a phar deserialization bug got bypassed with a path carrying one extra slash. The new flaw, CVE-2026-45034, is a 9.2 critical: full remote code execution on PHP 7.x and a file-read primitive on PHP 8.x. Here is how the bypass works and what your team should do this week.

Next.js just patched 13 security advisories. Self-hosted teams have the most work.

Vercel shipped a coordinated security release on May 7: 13 Next.js and React Server Components advisories covering DoS, SSRF, cache poisoning, and middleware bypasses in App Router. Self-hosted teams running Node are hit hardest. The deeper takeaway: middleware was never an authorization boundary.