[PR #3666] [MERGED] fix(deps): update dependency next to v15.3.3 [security] #21846

Closed
opened 2026-04-15 20:38:58 -05:00 by GiteaMirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/better-auth/better-auth/pull/3666
Author: @renovate[bot]
Created: 7/28/2025
Status: Merged
Merged: 7/30/2025
Merged by: @Bekacru

Base: mainHead: renovate/npm-next-vulnerability


📝 Commits (1)

  • cf3e0a0 fix(deps): update dependency next to v15.3.3 [security]

📊 Changes

3 files changed (+283 additions, -397 deletions)

View changed files

📝 docs/package.json (+1 -1)
📝 examples/nextjs-mcp/package.json (+1 -1)
📝 pnpm-lock.yaml (+281 -395)

📄 Description

This PR contains the following updates:

Package Change Age Confidence
next (source) 15.3.2 -> 15.3.3 age confidence
next (source) 15.2.3 -> 15.3.3 age confidence

GitHub Vulnerability Alerts

CVE-2025-49005

Summary

A cache poisoning issue in Next.js App Router >=15.3.0 and < 15.3.3 may have allowed RSC payloads to be cached and served in place of HTML, under specific conditions involving middleware and redirects. This issue has been fixed in Next.js 15.3.3.

Users on affected versions should upgrade immediately and redeploy to ensure proper caching behavior.

More details: CVE-2025-49005


Release Notes

vercel/next.js (next)

v15.3.3

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/better-auth/better-auth/pull/3666 **Author:** [@renovate[bot]](https://github.com/apps/renovate) **Created:** 7/28/2025 **Status:** ✅ Merged **Merged:** 7/30/2025 **Merged by:** [@Bekacru](https://github.com/Bekacru) **Base:** `main` ← **Head:** `renovate/npm-next-vulnerability` --- ### 📝 Commits (1) - [`cf3e0a0`](https://github.com/better-auth/better-auth/commit/cf3e0a0065f38b6bb8c69d6c37d17f1109e464a2) fix(deps): update dependency next to v15.3.3 [security] ### 📊 Changes **3 files changed** (+283 additions, -397 deletions) <details> <summary>View changed files</summary> 📝 `docs/package.json` (+1 -1) 📝 `examples/nextjs-mcp/package.json` (+1 -1) 📝 `pnpm-lock.yaml` (+281 -395) </details> ### 📄 Description This PR contains the following updates: | Package | Change | Age | Confidence | |---|---|---|---| | [next](https://nextjs.org) ([source](https://redirect.github.com/vercel/next.js)) | [`15.3.2` -> `15.3.3`](https://renovatebot.com/diffs/npm/next/15.3.2/15.3.3) | [![age](https://developer.mend.io/api/mc/badges/age/npm/next/15.3.3?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/next/15.3.2/15.3.3?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | [next](https://nextjs.org) ([source](https://redirect.github.com/vercel/next.js)) | [`15.2.3` -> `15.3.3`](https://renovatebot.com/diffs/npm/next/15.2.3/15.3.3) | [![age](https://developer.mend.io/api/mc/badges/age/npm/next/15.3.3?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/next/15.2.3/15.3.3?slim=true)](https://docs.renovatebot.com/merge-confidence/) | ### GitHub Vulnerability Alerts #### [CVE-2025-49005](https://redirect.github.com/vercel/next.js/security/advisories/GHSA-r2fc-ccr8-96c4) ### Summary A cache poisoning issue in **Next.js App Router >=15.3.0 and < 15.3.3** may have allowed RSC payloads to be cached and served in place of HTML, under specific conditions involving middleware and redirects. This issue has been fixed in **Next.js 15.3.3**. Users on affected versions should **upgrade immediately** and **redeploy** to ensure proper caching behavior. More details: [CVE-2025-49005](https://vercel.com/changelog/cve-2025-49005) --- ### Release Notes <details> <summary>vercel/next.js (next)</summary> ### [`v15.3.3`](https://redirect.github.com/vercel/next.js/compare/v15.3.2...v15.3.3) [Compare Source](https://redirect.github.com/vercel/next.js/compare/v15.3.2...v15.3.3) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/better-auth/better-auth). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS40MC4wIiwidXBkYXRlZEluVmVyIjoiNDEuNDAuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
GiteaMirror added the pull-request label 2026-04-15 20:38:58 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/better-auth#21846