{"url":"https://api.github.com/repos/vercel/next.js/releases/311649426","assets_url":"https://api.github.com/repos/vercel/next.js/releases/311649426/assets","upload_url":"https://uploads.github.com/repos/vercel/next.js/releases/311649426/assets{?name,label}","html_url":"https://github.com/vercel/next.js/releases/tag/v16.2.5","id":311649426,"author":{"login":"eps1lon","id":12292047,"node_id":"MDQ6VXNlcjEyMjkyMDQ3","avatar_url":"https://avatars.githubusercontent.com/u/12292047?v=4","gravatar_id":"","url":"https://api.github.com/users/eps1lon","html_url":"https://github.com/eps1lon","followers_url":"https://api.github.com/users/eps1lon/followers","following_url":"https://api.github.com/users/eps1lon/following{/other_user}","gists_url":"https://api.github.com/users/eps1lon/gists{/gist_id}","starred_url":"https://api.github.com/users/eps1lon/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/eps1lon/subscriptions","organizations_url":"https://api.github.com/users/eps1lon/orgs","repos_url":"https://api.github.com/users/eps1lon/repos","events_url":"https://api.github.com/users/eps1lon/events{/privacy}","received_events_url":"https://api.github.com/users/eps1lon/received_events","type":"User","user_view_type":"public","site_admin":false},"node_id":"RE_kwDOBC3Cis4Sk2SS","tag_name":"v16.2.5","target_commitish":"canary","name":"v16.2.5","draft":false,"immutable":false,"prerelease":false,"created_at":"2026-05-06T18:24:07Z","updated_at":"2026-05-12T08:11:43Z","published_at":"2026-05-06T18:54:20Z","assets":[],"tarball_url":"https://api.github.com/repos/vercel/next.js/tarball/v16.2.5","zipball_url":"https://api.github.com/repos/vercel/next.js/zipball/v16.2.5","body":"> [!NOTE]\r\n> This release contains security fixes and backported bug fixes. It does **not** include all pending features/changes on canary.\r\n\r\n### Security Fixes\r\n\r\nThe following advisories have been addressed:\r\n\r\n**High:**\r\n- [GHSA-8h8q-6873-q5fj: Denial of Service with Server Components](https://github.com/vercel/next.js/security/advisories/GHSA-8h8q-6873-q5fj)\r\n- [GHSA-267c-6grr-h53f: Middleware / Proxy bypass in App Router applications via segment-prefetch routes](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f)\r\n- [GHSA-mg66-mrh9-m8jx: Denial of Service via connection exhaustion in applications using Cache Components](https://github.com/vercel/next.js/security/advisories/GHSA-mg66-mrh9-m8jx)\r\n- [GHSA-492v-c6pp-mqqv: Middleware / Proxy bypass through dynamic route parameter injection](https://github.com/vercel/next.js/security/advisories/GHSA-492v-c6pp-mqqv)\r\n- [GHSA-c4j6-fc7j-m34r: Server-side request forgery in applications using WebSocket upgrades](https://github.com/vercel/next.js/security/advisories/GHSA-c4j6-fc7j-m34r)\r\n- [GHSA-36qx-fr4f-26g5: Middleware / Proxy bypass in Pages Router applications using i18n](https://github.com/vercel/next.js/security/advisories/GHSA-36qx-fr4f-26g5)\r\n\r\n**Moderate:**\r\n- [GHSA-ffhc-5mcf-pf4q: Cross-site scripting in App Router applications using CSP nonces](https://github.com/vercel/next.js/security/advisories/GHSA-ffhc-5mcf-pf4q)\r\n- [GHSA-gx5p-jg67-6x7h: Cross-site scripting in beforeInteractive scripts with untrusted input](https://github.com/vercel/next.js/security/advisories/GHSA-gx5p-jg67-6x7h)\r\n- [GHSA-h64f-5h5j-jqjh: Denial of Service in the Image Optimization API](https://github.com/vercel/next.js/security/advisories/GHSA-h64f-5h5j-jqjh)\r\n- [GHSA-wfc6-r584-vfw7: Cache poisoning in React Server Component responses](https://github.com/vercel/next.js/security/advisories/GHSA-wfc6-r584-vfw7)\r\n\r\n**Low:**\r\n- [GHSA-vfv6-92ff-j949: Cache poisoning via collisions in React Server Component cache-busting](https://github.com/vercel/next.js/security/advisories/GHSA-vfv6-92ff-j949)\r\n- [GHSA-3g8h-86w9-wvmq: Middleware / Proxy redirects can be cache-poisoned](https://github.com/vercel/next.js/security/advisories/GHSA-3g8h-86w9-wvmq)\r\n\r\n### Core Changes\r\n\r\n- fix: preserve HTTP access fallbacks during prerender recovery (#92231)\r\n- Fix fallback route params case in app-page handler (#91737)\r\n- Fix invalid HTML response for route-level RSC requests in deployment adapter (#91541)\r\n- Patch setHeader for direct route handlers (#93101)\r\n- Include deployment id in `cacheHandlers` keys (#93453)\r\n- Fix double-encoding of URL pathname parts in client param parsing (#93491)","reactions":{"url":"https://api.github.com/repos/vercel/next.js/releases/311649426/reactions","total_count":18,"+1":2,"-1":0,"laugh":0,"hooray":1,"confused":0,"heart":0,"rocket":8,"eyes":7}}