next
Version: 16.2.6The React Framework
What is next?
The React Framework
How to use this package
Quick install
Installs the package into the current environment for this session. Use --build or --runtime to persist it as a build-time or runtime dependency.
min add next Declare as a task dependency in minimal.toml
Listing the package under tasks.<name>.packages makes it available inside that task’s sandbox.
[tasks.dev]
packages = ["next"] Build-time vs runtime
Choose build-time for tools needed during compilation, runtime for dynamic libraries loaded at runtime.
min add --build next
min add --runtime next Dependencies (10)
No dependants
No other packages in the registry depend on this one.
No direct advisories
This package inherits 11 transitive advisories from its dependencies.
Showing 11 transitive advisories via next's dependencies
No advisories match the current filters.
| Status | IDs | Package | Severity | |||
|---|---|---|---|---|---|---|
| Critical ( 0 ) | ||||||
| High ( 9 ) | ||||||
| Affected: 2.42 | glibc | High: 7.5 | ||||
SummaryNo summary published for this advisory. Affected ranges
CVSS vector:
References | ||||||
| Affected: 2.42 | glibc | High: 7.5 | ||||
SummaryNo summary published for this advisory. Affected ranges
CVSS vector:
References | ||||||
| Affected: 2.42 | glibc | High: 8.4 | ||||
SummaryNo summary published for this advisory. Affected ranges
CVSS vector:
| ||||||
| Affected: 3.6.2 | openssl | High: 7.5 | ||||
SummaryNo summary published for this advisory. Affected ranges
CVSS vector:
References
| ||||||
| Resolved in v1.48.0 | libuv | High: 7.3 | ||||
SummaryImproper Domain Lookup that potentially leads to SSRF attacks in libuv Affected ranges
Fixed in:
CVSS vector:
References
| ||||||
| Resolved in 7.9.0* | node | High: 7.5 | ||||
Summarynpm packing does not respect root-level ignore files in workspaces Via: node Affected ranges
Fixed in:
CVSS vector:
References
| ||||||
| Resolved in 5b089951ac8e92670df03ddfaca5d5f2b7cbbebd | libvips | High | ||||
SummaryHeap-buffer-overflow in jxl::ModularFrameDecoder::DecodeGroup Via: libvips Affected ranges
Fixed in:
References | ||||||
| Resolved in 5b089951ac8e92670df03ddfaca5d5f2b7cbbebd | libvips | High | ||||
SummaryHeap-buffer-overflow in jxl::N_AVX2::SingleFromSingle Via: libvips Affected ranges
Fixed in:
References | ||||||
| Resolved in 0df65d82dbc41e8da00adb243de5918db532c8a6 | openssl | High | ||||
SummaryHeap-buffer-overflow in asn1_ex_i2c Affected ranges
Fixed in:
References | ||||||
| Medium ( 1 ) | ||||||
| Under investigation | libpng | Medium: 5.4 | ||||
SummaryLIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue. Affected ranges
CVSS vector:
| ||||||
| Low ( 1 ) | ||||||
| Resolved in 5b089951ac8e92670df03ddfaca5d5f2b7cbbebd | libvips | Low | ||||
SummaryUNKNOWN READ in void jxl::CopyImageTo<int> Via: libvips Affected ranges
Fixed in:
References | ||||||
| Unknown ( 0 ) | ||||||
72 components
No components match your filter.
| Packages | Version |
|---|---|
| next ROOT | 16.2.6 |
| acl | 2.3.2 |
| attr | 2.5.2 |
| autoconf | 2.73 |
| automake | 1.18.1 |
| bash | 5.3 |
| bash-bootstrap | 5.3 |
| binutils | 2.46.1 |
| bison | 3.8.2 |
| bzip2 | 1.0.8 |
| c-ares | 1.34.6 |
| cmake | 4.2.3 |
| coreutils | 9.11 |
| curl | 8.20.0 |
| diffutils | 3.12 |
| expat | 2.7.5 |
| file | 5.47 |
| findutils | 4.10.0 |
| flex | 2.6.4 |
| gawk | 5.4.0 |
| gawk-bootstrap | 5.3.2 |
| gcc | 15.2.0 |
| gdbm | 1.26 |
| glib | 2.86.4 |
| glibc | 2.42 |
| gmp | 6.3.0 |
| grep | 3.12 |
| gtest | 1.17.0 |
| gzip | 1.14 |
| icu | 78.3 |
| lcms2 | 2.17 |
| libcap | 2.78 |
| libffi | 3.5.2 |
| libidn2 | 2.3.8 |
| libjpeg-turbo | 3.1.4.1 |
| libpng | 1.6.58 |
| libpsl | 0.21.5 |
| libtool | 2.5.4 |
| libunistring | 1.4.1 |
| libuv | 1.52.1 |
| libvips | 8.18.3 |
| libwebp | 1.6.0 |
| lief | 0.17.6 |
| linux_headers | 6.12.43 |
| lz4 | 1.10.0 |
| m4 | 1.4.21 |
| make | 4.4.1 |
| meson | 1.10.1 |
| mpc | 1.4.0 |
| mpfr | 4.2.2 |
| ncurses | 6.5-20250830 |
| nghttp2 | 1.68.1 |
| nghttp3 | 1.15.0 |
| ngtcp2 | 1.22.1 |
| ninja | 1.13.2 |
| node | 25.8.2 |
| node-lts | 24.14.1 |
| openssl | 3.6.2 |
| pcre2 | 10.47 |
| perl | 5.42.0 |
| pkgconf | 2.5.1 |
| pnpm | 10.34.1 |
| python | 3.14.5 |
| readline | 8.3 |
| sed | 4.9 |
| setuptools | 82.0.1 |
| sqlite | 3.50.4 |
| tar | 1.35 |
| util-linux | 2.42.1 |
| xz | 5.8.3 |
| zlib | 1.3.2 |
| zstd | 1.5.7 |