Will there be a backport of security fixes for Next.js 14?
Unanswered
Bearded Collie posted this in #help-forum
Bearded CollieOP
I am not planning on upgrading to 15 because I do not need its features and due to how many vulnerabilities it has had
10 Replies
@Bearded Collie I am not planning on upgrading to 15 because I do not need its features and due to how many vulnerabilities it has had
yea, that happens when security issues are available
@B33fb0n3 yea, that happens when security issues are available
Bearded CollieOP
Wdym?
I see last release of 14 was 5 months ago so probably not 😢
like to answer your question:
Will there be a backport of security fixes for Next.js 14?yes
@Bearded Collie I see last release of 14 was 5 months ago so probably not 😢
some vulnabilities are also only available for newer versions. So dont worry
@B33fb0n3 like to answer your question:
> Will there be a backport of security fixes for Next.js 14?
yes
Bearded CollieOP
Oh ok, thanks
@B33fb0n3 some vulnabilities are also only available for newer versions. So dont worry
Bearded CollieOP
yup I just see a few that affect 13-16
yes, so when next14 is affected it will be backported ^^
@B33fb0n3 yes, so when next14 is affected it will be backported ^^
Bearded CollieOP
dont ones that affect 13 -> 16, affect 14 as well?
its very specific for the specific CVE. Each CVE contains the specific versions where its fixed and each minor version normally receives its own fix. For example for react2shell (cve-2025-55182) in the past (see attached)