Three bugs in vinext's alpha, Cloudflare's AI-built Next.js replacement
Three bugs in vinext's alpha, the Next.js replacement Cloudflare built with AI for about $1,100: a middleware auth bypass, a header-sanitization bypass, and a reflected XSS.
One column per disclosure, oldest on the left.
46 disclosures 40 CVEs since 2026-03 latest 2026-09-29
Three bugs in vinext's alpha, the Next.js replacement Cloudflare built with AI for about $1,100: a middleware auth bypass, a header-sanitization bypass, and a reflected XSS.
A white-box audit of the end-to-end encrypted booking platform OpenReception found 16 vulnerabilities, four of them critical.
How missing authorization checks in Zammad's REST API let agents execute group-restricted AI text tools and inject unauthorized ticket context into AI prompts.
QUIC stack enforces the stream-level but not the connection-level flow control limit, letting a remote peer make one connection allocate about 100 MB of heap instead of the 768 KiB window
missing authorization lets unauthenticated attackers use status, private, and private_only parameters to view draft, pending, trashed, or private event and location details
pre-authentication cluster header parsing lets one source IP allocate 256 MiB of manager memory per TCP connection
zlib decompression bomb in cluster archive processing lets an authenticated peer exhaust wazuh-clusterd memory
peer-controlled cluster hello node name lets an authenticated peer delete the contents of arbitrary manager directories on disconnect