Next.js formalizes security release process before upcoming patch
Vercel announced a formal Next.js security release program with defined disclosure windows, coordinated advisory publication, and pre-notification for enterprise support customers. The post signals an upcoming Next.js patch release. This ends the ad-hoc pattern where framework CVEs (middleware bypass, cache poisoning) landed with minimal advance notice.
Subscribe your on-call rotation to the new Next.js security channel now — if you're running Next.js in front of client marketing surfaces, you want the pre-notification path rather than reading GitHub advisories the morning of a release. Confirm your Vercel/self-host update process can turn a patch inside 24 hours.