Skip to content

framework

Next.js

Next.js is an open-source React framework from Vercel offering server-side rendering, routing, and build tooling for web applications.

Known aliases

  • create-next-app
  • Next
  • Next 15
  • next build
  • next dev
  • Next js
  • Next.js
  • Next.js 14
  • Next.js 15
  • Next.js 15.2.8
  • Next.js 16
  • Next.js 16.2.3
  • Next.js 16.3
  • Next.js 16.3.1
  • Next.js App Router
  • next/og

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

Chunked DELETE requests can smuggle a hidden second request through Next.js rewrites

Next.js's bundled http-proxy 1.18.1 stamps Content-Length: 0 on chunked DELETE and OPTIONS rewrites, so a hidden second request reaches the backend. Whether it reaches anything sensitive depends on how the next hop frames requests and which internal routes the backend opens to its proxy.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence56
build1 publisher

Satori's missing WOFF2 support puts four Geist .ttf files in a Next.js repo

Satori, the renderer behind next/og, cannot read WOFF2, so one Next.js site commits four Geist .ttf files to set its preview cards in the site's own type. The card takes its logo and palette from source, but its font is a second copy that someone has to keep current.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap0
Incentives20
Confidence50
build1 publisher

OpenAI's Node SDK defaults outlast Vercel's 300-second limit on a hung model call

OpenAI's Node SDK gives each attempt 10 minutes by default, so on Vercel a hung model call is killed at 300 seconds before its catch block can log anything. The call's own limits have to be shorter than every clock in front of it, or the platform ends the request and nothing gets recorded.

Publishers:dev.to

Reality

Evidence50
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence45
build1 publisher

An <object> tag turns an uploaded SVG into stored XSS for every visitor

OopsSec Store, a deliberately vulnerable Next.js app, lets an admin-uploaded SVG run JavaScript in every visitor's browser. It works because the server trusts the client-set Content-Type and the product page renders SVGs through an <object> tag.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives40
Confidence72

Earlier coverage

  1. The cancellation went into cancel_at while the dashboard read cancel_at_period_end

    Build · September 23, 2026 · 1 publisher

  2. Next.js 16 renames middleware.ts to proxy.ts, which always runs on the Node.js runtime

    Build · September 22, 2026 · 1 publisher

  3. The cheapest gate runs first so a flood stops before the Supabase auth call

    Build · September 22, 2026 · 1 publisher

  4. Five PHP-FPM workers capped an entire ride-hailing API at roughly 80 requests a second

    Build · September 21, 2026 · 1 publisher

  5. A five-minute function ceiling pushes long agent loops off Vercel's Hobby tier

    Build · September 21, 2026 · 1 publisher

  6. A bracket inside a folder name turned 1,200 Next.js pages into one encoded route

    Build · September 21, 2026 · 1 publisher

  7. A deploy that deletes old chunks leaves every open tab one click from a 404

    Build · September 20, 2026 · 1 publisher

  8. Next.js keeps a navigated static route in the browser for five minutes

    Build · September 20, 2026 · 1 publisher

  9. Invalidating a cache tag on one Next.js instance leaves the other one serving sold-out stock

    Build · September 19, 2026 · 1 publisher

  10. A log dashboard on default credentials hands over every plaintext password

    Build · September 19, 2026 · 1 publisher

  11. An audit of 23 AI-generated wiki sites found invented redeem codes on 18 of them

    Build · September 18, 2026 · 1 publisher

  12. Exiting zero on a failed FX fetch keeps yesterday's rates in the build

    Build · September 18, 2026 · 1 publisher

  13. Pooling per-job status polls into one Server Action cuts the client queue depth to one

    Build · September 17, 2026 · 1 publisher

  14. Upwork Scout signs its 15-minute login link and year-long unsubscribe token with one secret

    Build · September 17, 2026 · 1 publisher

  15. Arcjet puts a policy check in front of every action an AI agent takes

    Product · September 17, 2026 · 1 publisher

  16. Don Watch replays the 2019 Sheffield flood from gauge records inside one browser tab

    Build · September 17, 2026 · 1 publisher

  17. An HMAC-signed cookie and a license key carry all of Keyword Brief's billing state

    Build · September 17, 2026 · 1 publisher

  18. The globs line decides whether a Cursor rule ever reaches your route handler

    Build · September 16, 2026 · 1 publisher

  19. Markup filled 263,968 of a scraped product page's 267,361 tokens

    Build · September 16, 2026 · 1 publisher

  20. A 3,442-byte skill copy in a gitignored .gemini directory became a second source of truth

    Build · September 16, 2026 · 1 publisher

  21. Moving tenant isolation into Postgres policies buys zero rows instead of a cross-tenant leak

    Build · September 16, 2026 · 1 publisher

  22. React Compiler 1.0 skips any component that breaks the Rules of React

    Build · September 15, 2026 · 1 publisher

  23. Three hand-written route lists put /about in the sitemap and behind a login gate

    Build · September 15, 2026 · 1 publisher

  24. A singleton cron must list its tenants before a tenant filter has anything to bind to

    Build · September 15, 2026 · 1 publisher

  25. A CDN country header served Googlebot $14.99 on a page declaring GBP in its structured data

    Build · September 14, 2026 · 1 publisher

  26. Verifying Search Console at the bare domain summed four hosts into one 17% error rate

    Build · September 14, 2026 · 1 publisher

  27. Your Next.js hosting bill is a transform count, not a price list

    Build · August 20, 2026 · 1 publisher

  28. A try/catch around a Next.js server action swallows the redirect it was meant to protect

    Build · September 11, 2026 · 1 publisher

  29. A dev-server alias kept a cron handler out of the deployed Cloudflare Worker

    Build · September 11, 2026 · 1 publisher

  30. Seven hundred client fingerprints cover React2Shell's 8,163 source addresses

    Build · September 11, 2026 · 1 publisher

  31. Dropping a 6.6-second trace phase saved more build time than Turbopack's faster compile

    Build · September 11, 2026 · 1 publisher

  32. Algolia counts staging and locale indices against the same 10,000-record ceiling

    Build · September 11, 2026 · 1 publisher

  33. A remote MCP server spends five of its six routes on getting the client signed in

    Build · September 10, 2026 · 1 publisher

  34. Any path containing a dot skips LibreDB Studio's Next.js middleware

    Build · September 8, 2026 · 1 publisher

  35. Redefining done as 'prove the money path' made the agent provision its own infrastructure

    Build · September 8, 2026 · 1 publisher

  36. Keying the upsert on Stripe's id lets five code paths write one subscription row

    Build · September 6, 2026 · 1 publisher

  37. A 1.00 pages-per-visitor ratio caught the bots a user-agent block let through

    Build · September 6, 2026 · 1 publisher

  38. Next.js middleware's Edge Runtime default breaks Mongoose auth checks three different ways

    Build · September 6, 2026 · 1 publisher

  39. A cursor declaration in the route file gates the Pinia Colada adapter at compile time

    Build · September 5, 2026 · 1 publisher

  40. Turbopack's chunk merging pays off on the visitor who leaves after one page

    Build · September 4, 2026 · 1 publisher