Skip to content

Conversation

Copy link
Contributor

Copilot AI commented Jan 12, 2026

Next.js 14.2.4 contains four critical security vulnerabilities, including CVE-2025-29927 (CVSS 9.1) which allows middleware authorization bypass via forged x-middleware-subrequest headers.

Changes

  • Bump next from 14.2.4 to 14.2.35
  • Bump eslint-config-next from 14.2.4 to 14.2.35

Vulnerabilities Patched

Version 14.2.35 is the final patch release for Next.js 14.x (EOL October 2025).

Original prompt

Let's update Next.js to the latest supported version. (Do not change the major version.)
Before making changes, triple check on the internet for vulnerabilities and issues.


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

Copilot AI self-assigned this Jan 12, 2026
…abilities

Co-authored-by: peckz <18050177+peckz@users.noreply.github.com>
@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Jan 12, 2026

Deploying jam-dev-utilities with  Cloudflare Pages  Cloudflare Pages

Latest commit: 93179d8
Status: ✅  Deploy successful!
Preview URL: https://e5468946.jam-dev-utilities.pages.dev
Branch Preview URL: https://copilot-update-nextjs-to-lat.jam-dev-utilities.pages.dev

View logs

Copilot AI changed the title [WIP] Update Next.js to latest supported version Update Next.js 14.2.4 → 14.2.35 to patch critical security vulnerabilities Jan 12, 2026
Copilot AI requested a review from peckz January 12, 2026 13:19
@peckz peckz marked this pull request as ready for review January 12, 2026 13:32
@peckz peckz merged commit ae6570b into main Jan 12, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants