- Fix high‑severity Denial of Service in App Router via Server Actions Middleware and Turbopack proxy bypass
- Mitigate SSRF and cache‑confusion vulnerabilities in rewrites, request bodies (including invalid UTF‑8), and Server Actions on custom servers
- Patch DoS in Image Optimization API (SVG), unauthenticated disclosure of internal Server Function endpoints, and unbounded Server Action payloads in Edge runtime