FRAMESCAN
← FrameScan

Security blog

Framework CVEs, explained — and how to check if you're exposed.

Laravel Framework: Temporary Signed URL Path Confusion (GHSA-crmm-hgp2-wgrp) and CRLF Injection in Default Email Rule (GHSA-5vg9-5847-vvmq)

FrameScan now flags two high-severity Laravel 13 issues: temporary signed URL path confusion (fixed in 13.12.0) and CRLF injection in the default email rule (fixed in 13.10.0). Upgrade promptly.

FrameScan · 2026-07-22

Next.js high‑severity XSS and cache‑poisoning risks now detected (CVE-2026-44581, CVE-2026-44582)

Two high‑severity Next.js issues affect App Router projects: XSS when using CSP nonces and cache poisoning tied to React Server Component cache‑busting. Update to next 15.5.16. FrameScan already checks for both in upcoming scans.

FrameScan · 2026-07-22

Next.js CVE-2026-44579 and CVE-2026-44577: Denial of Service fixed in 15.5.16

FrameScan now detects two high-severity Next.js DoS issues affecting 10.0.0–15.5.15. Upgrade to next 15.5.16 to remediate. Your upcoming FrameScan run already includes these checks.

FrameScan · 2026-07-22

Next.js SSRF via WebSocket upgrades (CVE-2026-44578) and RSC cache poisoning (CVE-2026-44576) fixed in 15.5.16

FrameScan now flags two high-severity Next.js issues. Sites running affected versions should upgrade Next.js to 15.5.16 to address SSRF via WebSocket upgrades and cache poisoning in React Server Component responses.

FrameScan · 2026-07-22

Next.js CVE-2026-44573 (and related bypasses) fixed in 15.5.16

FrameScan now flags three High-severity Next.js middleware/proxy bypasses. Sites running affected versions should upgrade Next.js to 15.5.16 to close the gaps.

FrameScan · 2026-07-22

protobufjs: DoS in .proto option parsing and prototype mutation fixed in 7.6.5/8.6.5/8.6.6

FrameScan now flags three medium-severity protobufjs issues: two DoS bugs in .proto option parsing and a prototype mutation bug. Upgrade to 7.6.5 (v7) or 8.6.6 (v8) to resolve.

FrameScan · 2026-07-22

Axios vulnerabilities: prototype-polluted options (<0.33.0) and DoS via formDataToJSON (<1.18.0)

FrameScan now detects two medium-severity Axios issues: options objects can consume polluted prototype values (<0.33.0) and excessive recursion in formDataToJSON can cause DoS (<1.18.0). Upgrade to 0.33.0 or 1.18.0 as appropriate.

FrameScan · 2026-07-22

Django CVE-2026-25673 (URLField DoS) and four other high‑severity issues now detected

FrameScan now flags five high‑severity Django issues, including a URLField denial of service in 6.0.x and a race condition in file storage/caching. Upgrade to 6.0.3, 5.2.7, 5.1.1, or 1.0 as applicable. Your next scheduled FrameScan scan already checks for these.

FrameScan · 2026-07-22

React2Shell (CVE-2025-66478): how one HTTP request takes over a Next.js server

A CVSS 10.0 unauthenticated RCE in React Server Components. Here is exactly how it works, how to tell if you are affected, and how to fix it in minutes.

FrameScan · 2026-07-16