MikeTrendsTrends right now

search

Next.js

Trends

  1. 1
    Payload CMS vulnerability flagged with untrusted redirect flawโ—๐Ÿšจ EUVD-2026-93488 ๐Ÿ“Š Score: 6.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: next, next, payload (+1 more) ๐Ÿข Vendor: payloadcms, @payloadcmsMmastodonTechnologyCybersecurity06 h ago

    A medium-severity vulnerability, EUVD-2026-93488, has been catalogued affecting Payload CMS and related Next.js packages, with a CVSS v3.1 score of 6.1 out of 10. The flaw involves an untrusted redirect URL parameter exploit, which could let attackers craft malicious redirects. The advisory was updated on 6 October 2026 and is listed in the EU vulnerability database maintained by ENISA. Administrators running Payload or its Next.js integrations are advised to review the advisory and check for patches.

  2. 2
    Trusted Web Activity domain checks clash with Next.js routingโ—A Trusted Web Activity proves it owns a domain by fetching one file from one hard-coded path. Ours is a Next.js route haMmastodonTechnologyMobile216 h ago

    Android's Trusted Web Activity verifies that an app owns a domain by fetching a single file from a fixed, hard-coded path. Developers running Next.js are hitting a snag when their route handler sits one path segment away from that required location, producing a 404 that anyone can confirm in a browser. Web developers are debating workarounds for the mismatch.

Repos