# Next.js v16.2.4 → v16.2.5 Commit Analysis ## Statistics - **Total commits between tags**: 30 - **Security-related commits**: 12 - **Files changed**: 207 (5,797 insertions, 1,228 deletions) - **Source files (non-test, non-compiled)**: 54 ## Security-Related Commits | SHA | Subject | Likely Vulnerability Class | |-----|---------|----------------------------| | `0dd94836a8` | fix: add explicit checks for RSC header (#83) (#98) | RSC header spoofing / cache poisoning | | `d166096c39` | fix proxy matching for segment prefetch URLs (#89) (#96) | Auth bypass / SSRF / proxy bypass | | `9d50c0b719` | Strip next-resume header from incoming requests (#92) | Header injection / response smuggling | | `ed41d1d454` | Move htmlescape to shared/lib (#91) | XSS hardening (refactor for fix) | | `b4c6705c70` | Ignore malformed CSP nonce headers | CSP bypass / XSS | | `5b194ee2d4` | router-server: guard upgrade proxy against absolute-url SSRF (#77) | **SSRF** (websocket upgrade) | | `66f6017f15` | Escape properties for beforeInteractive scripts (#86) | **XSS** in `