1. Next.js 15.4.1-15.4.8: Critical RCE Flaw in React Server Components Exposes Servers to Unauthenticated Attack
A critical vulnerability in Next.js versions 15.4.1 through 15.4.8 allows unauthenticated attackers to execute arbitrary code on affected servers. The flaw resides in the React Server Components (RSC) payload decoding mechanism, enabling remote code execution (RCE) through specially crafted HTTP requests. Crucially, ex...