Menu

New deployments of vulnerable Next.js applications are now blocked by default - Vercel
📰
0

New deployments of vulnerable Next.js applications are now blocked by default - Vercel

Vercel News·Tom Knickman·4 days ago
#fZBwVBtm
Reading 0:00
15s threshold

Any new deployment containing a version of Next.js that is vulnerable to CVE-2025-66478 will now automatically fail to deploy on Vercel.

We strongly recommend upgrading to a patched version regardless of your hosting provider. Learn more

This automatic protection can be disabled by setting the DANGEROUSLY_DEPLOY_VULNERABLE_CVE_2025_66478=1 environment variable on your Vercel project. Learn more

Read More