Next.js 16.3.8 and 15.5.27 Patch Seven Vulnerabilities, Including a High-Severity Image Optimizer SSRF, While Two Others Slip
Vercel's Next.js team released 16.3.8 and 15.5.27 fixing one high, five medium and one low severity flaw; a critical and a high fix were postponed over upstream delays.
Overview
The Next.js team published its scheduled September security release on September 30, 2026. According to the Next.js blog, updates are now available in v16.3.8 (Active LTS) and v15.5.27 (Maintenance LTS). The release addresses seven vulnerabilities: one high, five medium, and one low in severity. The GitHub release for v16.3.8 lists the same set of fixes.
What We Know
The project gave advance notice. In a post on September 23, the team wrote that it was preparing a scheduled security release for September 30, 2026, to give teams time to plan upgrades. The notice was later updated to say the release would address seven vulnerabilities instead of nine, and that “The remaining two (one critical, one high) are pending upstream coordination and will be addressed in a later Next.js release.” The final announcement says a fix for one critical and one high severity vulnerability “was postponed due to upstream dependency delays.”
The advance notice also says Next.js 16.3.7, published September 29 with a bug fix, does not include the security fixes. The patches arrived in 16.3.8 and 15.5.27 instead.
The advisories break down as follows:
- High: Server-Side Request Forgery in Image Optimization (CVE-2026-94483). An attacker-controlled, allow-listed remote URL can lead to SSRF, for example to private IP ranges, during Image Optimization. If no
images.remotePatternsare configured, the application is not affected. - Medium: cache poisoning of SSG and ISR pages in self-hosted applications (CVE-2026-94543). Self-hosted applications using the Pages Router with statically generated or incrementally regenerated pages can have a page’s cache entry replaced with content from a different route. Applications deployed on Vercel are not affected.
- Medium: cross-user content substitution and persistent denial of service (CVE-2026-94484). Applications that use a root-level catch-all page together with SSG or ISR routes can have their shared response cache poisoned by a single unauthenticated crafted request.
- Medium: information disclosure in App Router metadata image routes (CVE-2026-94485). In webpack-built applications, routes such as
opengraph-imageandtwitter-imageignore thedynamicParamsoption. Applications built with Turbopack are not affected. - Medium: cache leak across root param values in nested
use cachefunctions (GHSA-h694-7cp9-m8p3). With Cache Components enabled, content produced for one root param value can be served for a different value. The advisory states that what values are leaked cannot be attacker controlled. - Medium: Draft Mode content leaking into regular responses (CVE-2026-94544). Pending
use cachefills are shared across requests for the same key without distinguishing Draft Mode requests. Sites are affected if they enable Cache Components (orexperimental.useCache) and serve Draft Mode previews. - Low: information disclosure in the development server’s Model Context Protocol endpoint (CVE-2026-94486). The
next devserver exposes an endpoint that does not verify which website a request originates from, so a malicious site visited by a developer could read data including the project’s location on disk, source code snippets from error reports, the route inventory, and development logs. Production deployments do not serve this endpoint.
The team’s recommended upgrade commands are npm install [email protected] for the 15.5 line and npm install [email protected] for the 16.3 line, per the release post.
What We Don’t Know
- The Next.js posts do not name the upstream dependency behind the postponement, nor describe the postponed critical and high-severity issues beyond their severity.
- No date has been given for the release that will carry those two fixes; the team says only that they will come in “a later Next.js release.”
- The posts do not say whether any of the seven issues has been exploited in the wild.
Context
The release follows an out-of-band fix earlier in the month for a different flaw, previously reported by The Machine Herald. The September 30 release is a separate scheduled batch and covers different issues.