October 3, 2026

Next.js security release: which advisories hit your app

Eight Next.js advisories since 22 Sept. See which apply to your config, which fix covers each, and how to patch to 16.3.8 or 15.5.27.

News

Tech

Backend

The Next.js security release comes down to one instruction: upgrade to 16.3.8 on the 16.3 line or 15.5.27 on the 15.5 line. How urgent that is depends on your config, because eight advisories landed across two dates, 22 September and 30 September 2026, and each one applies only under specific conditions. One is critical, one is high, five are medium and one is low. Some of them you can rule out from a single config check.

What Vercel shipped on 22 and 30 September

The first fix came on 22 September. Vercel's 22 September security update covers a critical remote code execution bug in the Node.js ImageResponse implementation from next/og, fixed in v16.3.6 (Active LTS) and v15.5.26 (Maintenance LTS). Only the 16.x fix is a real fix. The post says 15.5.26 "includes related hardening" and that Next.js 15.x isn't affected by the remote code execution issue.

The second batch came on 30 September. The September 2026 security release post lists seven advisories (the 23 September post gave the split as one high, five medium and one low) and says "updates are now available in v16.3.8 (Active LTS) and v15.5.27 (Maintenance LTS)." Those two versions are the targets.

Two intermediate versions are easy to mistake for the fix. Version 16.3.6 fixes the RCE and nothing from the 30 September batch. Version 16.3.7 was a bug-fix release: the upcoming-release post, published 23 September and updated by banners, says it "does not include the security fixes planned for September 30." If you patched to 16.3.7 last week, you're not done.

That same post carried a banner dated 30 September saying the remaining two (one critical, one high) were "pending upstream coordination" and would come in a later release. The 30 September release post says a fix for one critical and one high vulnerability "was postponed due to upstream dependency delays" and that updates in 16.3.8 and 15.5.27 "address these issues". Its Impact section lists seven advisories, with no critical among them, so it does not say which advisory the postponed critical is. This article's table covers every advisory the posts list.

If you came to 16.3 through the release covered in what Next.js 16.3 changed, the upgrade is still one command, now pinned to 16.3.8.

Which advisories apply to your app?

The table merges both dates. CVSS scores are v4, taken from GitHub's advisory records. GitHub labels the 6.3 items "Moderate"; the Next.js posts say "Medium", and so does this table. Affected ranges are as the advisory records state them.

AdvisorySeverity / CVSSAffected ifAffected versionsFixed inVercel-hosted
RCE in Node.js ImageResponse (GHSA-vcvr-r3jv-pc5j)Critical / 9.5Node.js ImageResponse renders attacker-controlled values in SVG content, attributes or styles. Edge ImageResponse isn't affected>=16.2.0 <16.3.616.3.6Not stated
SSRF in Image Optimization (GHSA-cjq9-62q9-8jv4)High / 8.3images.remotePatterns is configured. With none configured you're not affected>=16.0.016.3.8, 15.5.27Not stated
SSG/ISR cache replaced by another route's content (GHSA-4jqv-mc3x-m676)Medium / 6.3Self-hosted Pages Router app with SSG or ISR pages>=15.0.0 and >=16.0.015.5.27, 16.3.8Not affected (stated)
Shared cache poisoning via a root catch-all (GHSA-mcj8-r9mp-w47p)Medium / 6.3A root-level catch-all page plus SSG or ISR routes>=15.0.0 and >=16.0.015.5.27, 16.3.8Not stated
Metadata image routes ignoring dynamicParams (GHSA-f87g-xv8r-7p7x)Medium / 6.3App Router, webpack build, opengraph-image or twitter-image on dynamic segments left out of generateStaticParams(). Turbopack builds aren't affected>=16.0.016.3.8Not stated
Nested 'use cache' leaking across root params (GHSA-h694-7cp9-m8p3)Medium / 6.3cacheComponents: true, and a 'use cache' function calls another one that reads a root param16.3.0 only16.3.8Not stated
Draft Mode leak through pending use cache fills (GHSA-3w37-wq28-93x7)Medium / 6.3Cache Components (or experimental.useCache) and Draft Mode previews whose cached functions return draft-dependent content16.3.0 only16.3.8Not stated
Information disclosure in the next dev MCP endpoint (GHSA-39w2-rjm5-chcv)Low / 2.3You run next dev. Production doesn't serve the endpoint>=16.0.016.3.8N/A (dev server)

Row 1's score and range come from the advisory record, not the blog. The nested 'use cache' advisory was updated on 1 October and now carries CVE-2026-103004, according to GitHub's record; the 30 September post lists it by advisory ID only.

Checking each condition in your codebase

Is images.remotePatterns configured?

Open next.config.js or next.config.ts and look under images. The 30 September post says that if no images.remotePatterns are configured, your application isn't affected by the SSRF issue. If you have patterns, the advisory's workaround is to audit the allow-listed hosts for any that may not be trusted with their DNS entries. That narrows exposure. It doesn't replace the upgrade.

Bash
grep -rn "remotePatterns" next.config.*

Is the Pages Router app self-hosted with SSG or ISR, or does it have a root catch-all?

Two advisories live here, and both need a cache to poison. The first applies to self-hosted Pages Router apps with SSG or ISR pages; the post says applications deployed on Vercel aren't affected. The second concerns a root-level catch-all page next to SSG or ISR routes, where the post says the shared response cache can be poisoned "by a single unauthenticated crafted request." Catch-all pages use the [...slug] or [[...slug]] file naming in pages/. The cache-poisoning advisory doesn't state a Vercel exemption, so a Vercel-hosted app with a root catch-all shouldn't assume one.

Is it a webpack or Turbopack build with metadata image routes?

The post says applications built with Turbopack aren't affected. On webpack, check whether any dynamic segment has an opengraph-image or twitter-image route and whether that segment is excluded from generateStaticParams(). If both are true, you're in scope. This is the only advisory in the set that a bundler choice removes.

Does the app use Cache Components, 'use cache' or Draft Mode?

Search for cacheComponents: true in your config and for 'use cache' directives. For the nested case, a function marked 'use cache' has to call another that reads a root param. The advisory says the leaked values can't be attacker-controlled, and that there are no known workarounds: apps should upgrade as soon as possible. For Draft Mode, you're affected if you enable Cache Components (or experimental.useCache) and serve previews whose cached functions return draft-dependent content. Both advisory records list 16.3.0 as the only affected version.

Does next/og render user input on the Node.js runtime?

This is the critical one. Look for ImageResponse imported from next/og in routes that run on the Node.js runtime, then check whether anything a user controls ends up in SVG content, attributes or styles. Edge ImageResponse isn't affected. If you can't upgrade yet, the advisory's workaround reads: "If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js ImageResponse implementation from next/og."

Does a website you visit while running next dev matter?

The low-severity issue is an information disclosure in the MCP endpoint that next dev serves. The post says production deployments don't serve it. It matters on a developer machine, so upgrade there, but it doesn't change your production risk.

How to upgrade Next.js to 16.3.8 or 15.5.27

1. Find your current version

Run npm ls next in the project root. This command is a convenience step, not something the Next.js posts provide.

Bash
npm ls next
text
my-app@0.1.0 /path/to/my-app
└── next@16.3.5

2. Pick your line

If the output starts with 16.3, you're on the Active LTS line and the target is 16.3.8. If it starts with 15.5, you're on Maintenance LTS and the target is 15.5.27. The release post names fixes for these two lines only.

3. Run the vendor's command

These are the commands from the 30 September post:

Bash
npm install next@16.3.8   # for 16.3
npm install next@15.5.27  # for 15.5

4. Rebuild, redeploy and purge cached pages

Rebuild and redeploy as usual. For self-hosted apps, also clear your ISR and shared cache entries. This purge step is HighCircl's inference, not a vendor instruction: the cache advisories describe bad entries persisting until revalidated, so an old poisoned entry could outlive the patch if nothing revalidates it. How you clear the cache depends on your deployment, and the posts don't prescribe a method.

5. Re-run the checks

Go back through the table above with the new version number. If you can't upgrade for the critical ImageResponse issue, apply the advisory's workaround quoted earlier until you can.

What the advisories do not tell you

Only one advisory states a Vercel exemption, the Pages Router cache replacement. For the rest, the advisories don't say, so "Not stated" in the table means exactly that and not "affected". Upgrade anyway.

The 15.x scope varies by record. The advisory records list 15.x only for the two cache advisories; the SSRF, metadata, MCP and use cache records start at 16.0.0 or 16.3.0. Don't read that as a guarantee for your 15.5 app beyond what the records say.

The fixed versions need one caution. Six of the eight advisory pages show a placeholder where the patched version should be, so the 16.3.8 and 15.5.27 targets for those come from the release post, not from the advisory pages. Only the nested 'use cache' and RCE advisories name their fixed versions themselves. The posts also don't claim exploitation in the wild, and neither does this article.

If your team is also working through other vendors' patches this month, GitLab's 19.4.1 patch triage follows the same critical-plus-patch-path shape, and apps built from the streaming Claude chat tutorial were built and tested on 16.3.8, so they already carry the 30 September fixes. Release notes like these are collected in Platform and language release notes: what breaks and what to fix.

FAQ

Is Next.js 16.3.6 enough?

No. Version 16.3.6 fixes only the critical ImageResponse RCE. The seven advisories from 30 September need 16.3.8 or 15.5.27, and 16.3.7 carried no security fixes.

Are Vercel-hosted apps affected?

One advisory, the Pages Router SSG and ISR cache replacement, is stated not to affect Vercel deployments. The advisories don't say either way for the others. Upgrade regardless.

Is an upgrade needed without images.remotePatterns?

You're not affected by the high-severity SSRF issue. The other advisories depend on your setup (Pages Router, catch-all pages, Cache Components, Draft Mode, next/og, next dev), so check each row of the table before deciding the rest can wait.

Does Turbopack avoid all of this?

No. The post says Turbopack builds aren't affected by the metadata image routes advisory, and nothing in the set grants Turbopack a blanket exemption.

Is next dev exposure a production risk?

No. The advisory says production deployments don't serve the MCP endpoint. The exposure is on machines running next dev.

Share this article

Author Image

HighCircl Editorial Team

The HighCircl editorial team writes about hiring software engineers, nearshore development, and engineering team building. Our articles draw on direct experience sourcing and placing senior developers across Poland, Hungary, Slovakia, Serbia, Slovenia, Romania, and Spain — and on candid conversations with the CTOs and engineering leads who hire them.

HighCircl is a nearshore engineering network that delivers matched candidate shortlists in 72 hours. Every piece of content we publish is informed by real engagement data: actual developer rates, real hiring timelines, and what separates engineering teams that scale cleanly from those that stall.

Take Me to the Experts

Access our network of industry-leading software engineers.

Start Now