Web Programming

Patch nowJS & TypeScript

Next.js 16.3.8 fixes seven vulnerabilities, with a critical fix still to come

Issue #2

On September 30 Next.js released 16.3.8 and 15.5.27. The high-severity fix is an SSRF in Image Optimization, and a critical fix was postponed.

Karlen TriminoSenior Full-Stack Engineer

Leer en español
Photo: Nemuel Sereti / Pexels

What to do

Upgrade to 16.3.8 or 15.5.27, and plan for another Next.js release soon: a critical and a high fix are still waiting on an upstream dependency.

Key facts

Severity
High
Fixed in
16.3.8, 15.5.27
Advisory IDs
CVE-2026-94483, GHSA-cjq9-62q9-8jv4

On September 30 Next.js released 16.3.8 (Active LTS) and 15.5.27 (Maintenance LTS), fixing seven vulnerabilities. The high-severity one, CVE-2026-94483, is a server-side request forgery in Image Optimization: an attacker-controlled, allow-listed remote URL can reach private IP ranges. If you don't configure images.remotePatterns, you're not affected.

The medium ones cover cache poisoning of SSG and ISR pages, metadata image routes that ignore dynamicParams in webpack builds, and two 'use cache' leaks, one of which can expose Draft Mode content. The low one is worth knowing: the next dev server's MCP endpoint didn't check which website a request came from, so a malicious page you visit while developing could read your project's location, routes and logs.

Vercel also says a fix for one critical and one high vulnerability was postponed because of upstream dependency delays.

Sources