Skip to content

Conversation

@knqyf263
Copy link
Collaborator

@knqyf263 knqyf263 commented Dec 5, 2025

Summary

  • Add vulnerability data for GHSA-9qr9-h5gf-34mp (Next.js RCE in React flight protocol)
  • Use CVE-2025-55182 as the alias instead of CVE-2025-66478 which was rejected by CNA
  • This enables proper vulnerability detection for affected Next.js versions

Related Issue

Closes aquasecurity/trivy-db#597

Test plan

  • Validated with osv-linter (v1.6.7)

@knqyf263 knqyf263 marked this pull request as ready for review December 5, 2025 07:18
@DmitriyLewen
Copy link
Contributor

DmitriyLewen commented Dec 5, 2025

Trivy correctly detects this vulnerability:

├────────────────────┼─────────────────────┼──────────┤        ├───────────────────┼────────────────────────────────────────────────────────┼───────────────────────────────────────────────────────────┤
│ next               │ GHSA-9qr9-h5gf-34mp │ CRITICAL │        │ 16.0.0            │ 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7 │ Next.js is vulnerable to RCE in React flight protocol     │
│                    │                     │          │        │                   │                                                        │ https://github.com/advisories/GHSA-9qr9-h5gf-34mp         │
└────────────────────┴─────────────────────┴──────────┴────────┴───────────────────┴────────────────────────────────────────────────────────┴───────────────────────────────────────────────────────────┘

@DmitriyLewen DmitriyLewen merged commit d3eac6d into main Dec 5, 2025
2 checks passed
@DmitriyLewen DmitriyLewen deleted the react2shell branch December 5, 2025 07:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Missing next.js GHSA-9qr9-h5gf-34mp

3 participants