Next.js 16.3.8 / 15.5.27 Fix 7 Security Advisories
On September 30, 2026 Vercel published the scheduled security release we flagged
at the end of last week's out-of-band next/og
patch. The patched versions are 16.3.8 and
15.5.27, and between them they close seven advisories: one High, five
Moderate and one Low. Only one is a classic exploit primitive — a server-side
request forgery in Image Optimization. The other six are cache and disclosure
bugs, which is a less dramatic category and a more likely one to actually bite
you in production.
If you are on the 16.x line you want all seven fixes, so upgrade to 16.3.8. If
you are on 15.x, three of the Moderate advisories apply to you and 15.5.27 is the
target. The High-severity SSRF affects >= 16.0.0 only — Next.js 15 is not
in range.
The High one: SSRF in Image Optimization
CVE-2026-94483 is scored 8.3 (High) on CVSS v4. The advisory's impact statement is one sentence:
An attacker-controlled, allow-listed remote URL can lead to server-side request forgery (e.g. to private IPs) during Image Optimization.
The prerequisite is in the word allow-listed. The optimizer only fetches remote
images from hosts listed in images.remotePatterns, so the attack starts from a
host you already trust. If an attacker can influence DNS resolution for one of
those hostnames, the optimizer can be steered at addresses inside your network
and used as a proxy for them.
That dependency on an external condition is why the score stops at 8.3: the vector carries both a High attack complexity and an attack requirement. Network reachable, no privileges, no user interaction — but not a bug you can fire blind at an arbitrary Next.js install.
The advisory's stopgap, if you cannot deploy today:
Audit allow-listed remote URLs in
images.remotePatternsfor hosts that may not be trusted with their DNS entries. If noimages.remotePatternsare configured, your app is not affected.
That last clause is the fastest triage step in the whole release. Open
next.config.ts; no remotePatterns, no exposure.
Four cache bugs with two different root causes
The Moderate advisories split cleanly into two groups, and which group matters to you depends on which router and which caching model you are running.
Pages Router and self-hosting
CVE-2026-94543 (6.3) hits self-hosted applications using the Pages Router with SSG or ISR pages. An attacker can get a page's cache entry replaced with content from a different route, and the wrong content is then served to every visitor until that entry is revalidated. The CVSS metrics rate the impact as availability-only, which undersells how it looks to a customer hitting your pricing page.
CVE-2026-94484 (6.3) is the same family with a different trigger: a root-level catch-all page combined with SSG or ISR routes. An unauthenticated request can poison the shared response cache, producing cross-user content substitution and a denial of service that persists in the cache rather than ending when the attacker stops.
Both affect 15.x and 16.x. If you self-host a Pages Router app — and the point of self-hosting is that no managed platform absorbs this class of bug for you — these two are the reason to schedule the upgrade.
Cache Components
The other two need Cache Components or experimental.useCache turned on, so they
affect a much narrower set of applications on 16.x.
CVE-2026-94544
(6.3) is a Draft Mode leak. Pending use cache fills were shared between
overlapping requests without distinguishing an authenticated Draft Mode request
from an ordinary one. A regular visitor whose request overlaps an editor's preview
can be served unpublished content with no authentication at all — and if that
request triggers on-demand prerendering, the draft gets persisted into the
generated page for everyone after them.
CVE-2026-103004
(6.3) is a cache-key defect. When a 'use cache' function calls another
'use cache' function that reads root params, and the inner call is served from
cache, the outer function's key omits the root param value. One entry then gets
reused across different root params. If you key tenancy or locale off root
params, that is exactly the boundary you did not want collapsed — and downstream
CDNs will spread the mismatch.
Two information disclosures
CVE-2026-94485
(6.3, >= 16.0.0) is a dynamicParams bypass in webpack-built App Router apps.
Metadata image routes — opengraph-image, twitter-image — ignored the
dynamicParams route segment option, so segments you deliberately excluded from
static generation could still be requested as images.
CVE-2026-94486
is the one Low (2.3), and it is development-only: the dev server's Model Context
Protocol endpoint did not verify request origin. A malicious site visited while
next dev is running could read back your project's path on disk, source
snippets from error reports, your route inventory and dev logs. Production is
unaffected — but it is a reminder that the local tooling surface AI agents talk
to is now part of your attack surface.
Upgrading
npm install next@16.3.8 # 16.x line — all seven fixes
npm install next@15.5.27 # 15.x line — three Moderate fixes
One note if you were expecting a different version number: we told you to plan for 16.3.7. That number got spent a day earlier, on September 29, by an unrelated Turbopack bug-fix backport, so the security release landed as 16.3.8.
Self-hosting a Pages Router app with ISR, or running Cache Components in production and unsure which of these four cache paths you are exposed to? Get in touch — auditing and patching Next.js deployments is what we do.