Blog / 01

Next.js 16.3.8 / 15.5.27 Fix 7 Security Advisories

WebRestart

On September 30, 2026 Vercel published the scheduled security release we flagged at the end of last week's out-of-band next/og patch. The patched versions are 16.3.8 and 15.5.27, and between them they close seven advisories: one High, five Moderate and one Low. Only one is a classic exploit primitive — a server-side request forgery in Image Optimization. The other six are cache and disclosure bugs, which is a less dramatic category and a more likely one to actually bite you in production.

If you are on the 16.x line you want all seven fixes, so upgrade to 16.3.8. If you are on 15.x, three of the Moderate advisories apply to you and 15.5.27 is the target. The High-severity SSRF affects >= 16.0.0 only — Next.js 15 is not in range.

The High one: SSRF in Image Optimization

CVE-2026-94483 is scored 8.3 (High) on CVSS v4. The advisory's impact statement is one sentence:

An attacker-controlled, allow-listed remote URL can lead to server-side request forgery (e.g. to private IPs) during Image Optimization.

The prerequisite is in the word allow-listed. The optimizer only fetches remote images from hosts listed in images.remotePatterns, so the attack starts from a host you already trust. If an attacker can influence DNS resolution for one of those hostnames, the optimizer can be steered at addresses inside your network and used as a proxy for them.

That dependency on an external condition is why the score stops at 8.3: the vector carries both a High attack complexity and an attack requirement. Network reachable, no privileges, no user interaction — but not a bug you can fire blind at an arbitrary Next.js install.

The advisory's stopgap, if you cannot deploy today:

Audit allow-listed remote URLs in images.remotePatterns for hosts that may not be trusted with their DNS entries. If no images.remotePatterns are configured, your app is not affected.

That last clause is the fastest triage step in the whole release. Open next.config.ts; no remotePatterns, no exposure.

Four cache bugs with two different root causes

The Moderate advisories split cleanly into two groups, and which group matters to you depends on which router and which caching model you are running.

Pages Router and self-hosting

CVE-2026-94543 (6.3) hits self-hosted applications using the Pages Router with SSG or ISR pages. An attacker can get a page's cache entry replaced with content from a different route, and the wrong content is then served to every visitor until that entry is revalidated. The CVSS metrics rate the impact as availability-only, which undersells how it looks to a customer hitting your pricing page.

CVE-2026-94484 (6.3) is the same family with a different trigger: a root-level catch-all page combined with SSG or ISR routes. An unauthenticated request can poison the shared response cache, producing cross-user content substitution and a denial of service that persists in the cache rather than ending when the attacker stops.

Both affect 15.x and 16.x. If you self-host a Pages Router app — and the point of self-hosting is that no managed platform absorbs this class of bug for you — these two are the reason to schedule the upgrade.

Cache Components

The other two need Cache Components or experimental.useCache turned on, so they affect a much narrower set of applications on 16.x.

CVE-2026-94544 (6.3) is a Draft Mode leak. Pending use cache fills were shared between overlapping requests without distinguishing an authenticated Draft Mode request from an ordinary one. A regular visitor whose request overlaps an editor's preview can be served unpublished content with no authentication at all — and if that request triggers on-demand prerendering, the draft gets persisted into the generated page for everyone after them.

CVE-2026-103004 (6.3) is a cache-key defect. When a 'use cache' function calls another 'use cache' function that reads root params, and the inner call is served from cache, the outer function's key omits the root param value. One entry then gets reused across different root params. If you key tenancy or locale off root params, that is exactly the boundary you did not want collapsed — and downstream CDNs will spread the mismatch.

Two information disclosures

CVE-2026-94485 (6.3, >= 16.0.0) is a dynamicParams bypass in webpack-built App Router apps. Metadata image routes — opengraph-image, twitter-image — ignored the dynamicParams route segment option, so segments you deliberately excluded from static generation could still be requested as images.

CVE-2026-94486 is the one Low (2.3), and it is development-only: the dev server's Model Context Protocol endpoint did not verify request origin. A malicious site visited while next dev is running could read back your project's path on disk, source snippets from error reports, your route inventory and dev logs. Production is unaffected — but it is a reminder that the local tooling surface AI agents talk to is now part of your attack surface.

Upgrading

npm install next@16.3.8   # 16.x line — all seven fixes
npm install next@15.5.27  # 15.x line — three Moderate fixes

One note if you were expecting a different version number: we told you to plan for 16.3.7. That number got spent a day earlier, on September 29, by an unrelated Turbopack bug-fix backport, so the security release landed as 16.3.8.


Self-hosting a Pages Router app with ISR, or running Cache Components in production and unsure which of these four cache paths you are exposed to? Get in touch — auditing and patching Next.js deployments is what we do.