MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 5 h ago, last 5 h ago, peak #6

Progress Software discloses SSRF flaw in Sitefinity Next.js SDK

Original: CVE-2026-92931: Progress Software reports a server-side request forgery flaw in its Sitefinity Next.js SDK npm package.

Progress Software has disclosed CVE-2026-92931, a server-side request forgery vulnerability in the Sitefinity Next.js SDK npm package. According to the advisory, a remote attacker could trick the server into making requests to an attacker-controlled host, potentially exposing sensitive information. Affected versions reportedly begin with 15.1.8326, and developers using the package are being urged to review their installations.

Why now: Security teams are discussing the newly published advisory so they can assess whether their applications use the affected package.

Progress SoftwareSitefinityNext.js SDKnpmCVE-2026-92931

Open on mastodon →

Rank over time, top of the chart is #1. 2 snapshots from 5 h ago to 5 h ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1115072