Four Critical CVEs, the Same Trust Issue
Patchnext (npm)sharp (npm)Our summary
Ongoing security updates have addressed four critical vulnerabilities in widely used infrastructure components, including two distinct issues within the next npm package, one in io.netty:netty-handler, and one in GitPython. These unauthenticated flaws enable severe impacts such as remote code execution via heap overflow in libheif, path traversal on Windows servers exposing encryption keys, mutual TLS (mTLS) bypass, and arbitrary code execution through git hooks.
Developers should immediately upgrade to the fixed releases: update next to version 15.5.24 or 16.3.3, sharp to 0.35.4, libheif to 1.23.2, io.netty:netty-handler to 4.1.137.Final or 4.2.17.Final, and GitPython to 3.1.59. The associated identifiers are CVE-2026-75604, CVE-2026-75595, and CVE-2026-78676.
Below is the opening; the full story is at OX Security.
From OX Security
Last week, 4 unauthenticated critical CVEs turned up in 24 hours, all sharing the same mistake: a component trusting the layer next to it
Within a single 24-hour window last week, four critical vulnerabilities landed across widely deployed infrastructure: two in Next.js, one in Netty, one in GitPython. All four are remotely reachable, all four require no authentication, and three of the four sit in code paths that are on by default.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.