Blog / 02

Next.js 16.3.8 Fixes 7 Flaws: SSRF, Cache Poisoning

WebRestart

On September 30, 2026 at 16:13 UTC Vercel published 16.3.8 and 15.5.27, the scheduled security release that had been pre-announced a week earlier. Seven advisories: one High, five Moderate, one Low. If you self-host, the two cache-poisoning issues are the ones to read first — they are the only advisories in this batch whose affected range includes the 15.x line, and they do not require an authenticated attacker.

Two details differ from the pre-announcement, which is worth noting because the earlier version numbers are already circulating. The patch landed as 16.3.8, not 16.3.7 — 16.3.7 shipped a day earlier on September 29 as an unrelated turbo-tasks-backend backport. And the advisory count came in at seven rather than the nine the heads-up mentioned.

The one High: SSRF in Image Optimization

CVE-2026-94483 (CVSS 8.3) lets an attacker drive server-side requests at private IP ranges through the Image Optimization pipeline. The affected range is >= 16.0.0 < 16.3.8; the 15.x line is not in scope.

The precondition is narrower than the score suggests. You are exposed only if images.remotePatterns is configured, and only if one of the hosts you allow-listed can be influenced by someone else — the advisory's phrasing is an "attacker-controlled, allow-listed remote URL." The abuse is at the DNS layer: a host you trust resolves somewhere you did not intend, and the optimizer follows it. That requirement is visible in the CVSS v4 vector, CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N, where AC:H and AT:P both mark conditions that have to line up. Apps with no remotePatterns entry are unaffected.

The stopgap, if you cannot deploy today, is an audit rather than a config flag: walk your remotePatterns list and ask, for each host, who controls its DNS. Wildcard patterns over a domain you do not own are the shape to look for.

Two cache-poisoning bugs, and these reach Next.js 15

Both are rated Moderate at CVSS 6.3, both are self-hosted-only — Vercel-hosted applications are not affected — and both are patched in 15.5.27 as well as 16.3.8.

CVE-2026-94543 affects Pages Router applications serving statically generated or incrementally regenerated pages. A page's cache entry can be replaced with content from a different route, and the wrong content is then served to every visitor until that entry is revalidated.

CVE-2026-94484 is the same class with a different trigger: a root-level catch-all page combined with SSG or ISR routes. One unauthenticated request is enough to poison the shared response cache, producing cross-user content substitution and — because the poisoned entry persists — a durable denial of service.

Rated Moderate, but note what that rating is measuring. A single unauthenticated request that makes a public route serve the wrong page to everyone, indefinitely, is not a 6.3-shaped problem for a content site or a marketing funnel. The severity score describes the mechanism; the blast radius depends on what your cached routes are for.

Three Cache Components issues

The remaining Moderate advisories all sit in newer App Router surface area.

  • GHSA-h694-7cp9-m8p3 (CVSS 6.3, no CVE assigned) — a cache-keying bug in nested 'use cache' functions. When an inner cached function reads a root param and is served from an existing entry, the enclosing function's cache key omits that root param, so one entry gets reused across different root param values. The advisory is explicit that an attacker cannot choose which values leak: whichever invocation wrote the entry first decides what everyone else sees. Shared cache headers let downstream caches spread it further.
  • CVE-2026-94544 (6.3) — pending use cache fills are shared between Draft Mode and regular requests. A regular request overlapping a Draft Mode request can receive unpublished content with no authentication, and if the overlap triggers on-demand prerendering, that unpublished content persists into the generated page. Relevant if you use Cache Components or experimental.useCache together with Draft Mode previews.
  • CVE-2026-94485 (6.3) — App Router metadata image routes (opengraph-image, twitter-image) built with webpack do not honour the dynamicParams segment config. Metadata images can be requested for dynamic segments deliberately left out of generateStaticParams(). The advisory lists >= 16.0.0 as affected; the fix also ships in 15.5.27.

The Low one only bites in development

CVE-2026-94486 (CVSS 2.3) is an origin-verification gap on the next dev server's Model Context Protocol endpoint. A malicious site visited while your dev server is running can read project file paths, route information, source excerpts from error messages and dev server logs. Production builds do not expose the endpoint — but it is a reminder that next dev has grown a locally reachable API surface worth treating like one.

What to upgrade to

# 16.x line
npm install next@16.3.8

# 15.5 line
npm install next@15.5.27

As with last week's out-of-band 16.3.6, take the latest patch in your minor rather than pinning to the exact version named in an advisory — this line has been moving weekly. There are no back-patches for 13.x or 14.x.

Once patched, do the remotePatterns audit anyway. The SSRF itself is fixed, but an allow-list containing hosts whose DNS you do not control keeps resurfacing in advisories about this subsystem — it already did in July's CVE-2026-64644.

Primary sources: the Next.js security advisories on GitHub and the v16.3.8 and v15.5.27 release notes.


Self-hosting Next.js with SSG or ISR routes and unsure whether the cache-poisoning advisories apply to your setup? Get in touch — auditing and upgrading Next.js deployments is what we do.