Patch released next (npm) rce sharp (npm) Next.js auth-bypass
Four Critical CVEs, the Same Trust Issue
Last week, 4 unauthenticated critical CVEs turned up in 24 hours, all sharing the same mistake: a component trusting the layer next to it
Within a single 24-hour window last week, four critical vulnerabilities landed across widely deployed infrastructure: two in Next.js, one in Netty, one in GitPython. All four are remotely reachable, all four require no authentication, and three of the four sit in code paths that are on by default.…