Skip to content

fix: Upgrade next to fix HTTP deserialization DoS#11597

Merged
anthonyshew merged 2 commits intomainfrom
fix/TURBO-5147-next-vulnerability
Jan 31, 2026
Merged

fix: Upgrade next to fix HTTP deserialization DoS#11597
anthonyshew merged 2 commits intomainfrom
fix/TURBO-5147-next-vulnerability

Conversation

@anthonyshew
Copy link
Copy Markdown
Contributor

Summary

Upgrades next from 16.1.1 to 16.1.5 in docs/site to fix a high severity HTTP request deserialization DoS vulnerability.

Vulnerability Details

  • Package: next >=16.1.0-canary.0 <16.1.5
  • Issue: HTTP request deserialization DoS
  • Severity: High
  • Dependency Path: docs/site > next

Changes

  • Updated next version in docs/site/package.json from 16.1.1 to 16.1.5
  • Updated pnpm-lock.yaml accordingly

Fixes TURBO-5147

@anthonyshew anthonyshew requested a review from a team as a code owner January 31, 2026 20:41
@anthonyshew anthonyshew requested review from tknickman and removed request for a team January 31, 2026 20:41
@vercel
Copy link
Copy Markdown
Contributor

vercel Bot commented Jan 31, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
examples-basic-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:41pm
examples-designsystem-docs Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:41pm
examples-gatsby-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:41pm
examples-kitchensink-blog Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:41pm
examples-nonmonorepo Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:41pm
examples-svelte-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:41pm
examples-tailwind-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:41pm
examples-vite-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:41pm
turbo-site Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:41pm
turborepo-test-coverage Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:41pm

@ghost ghost added the area: site Issues and improvements related to Turborepo's documentation website label Jan 31, 2026
@github-actions
Copy link
Copy Markdown
Contributor

Coverage Report

Metric Coverage
Lines 75.88%
Functions 46.74%
Branches 0.00%

View full report

@anthonyshew anthonyshew merged commit 4b04a3b into main Jan 31, 2026
48 checks passed
@anthonyshew anthonyshew deleted the fix/TURBO-5147-next-vulnerability branch January 31, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: site Issues and improvements related to Turborepo's documentation website

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant