Patch now
Security fixes to apply now.
Next.js 16.3.6 fixes a critical remote code execution flaw in next/og
The September 22 release fixes a critical RCE in the Node.js ImageResponse of next/og. Versions 16.2.0 up to 16.3.5 are affected.
PHP fixes an SQL injection in the pg_* functions
CVE-2026-17543 (High) is an SQL injection in pg_insert, pg_update, pg_select and pg_delete. It was fixed in the July 30 releases.
Node.js July security releases fixed 11 CVEs, three rated High
The July 29 security releases (26.5.1, 24.18.1, 22.23.2) fixed 11 CVEs, three of them rated High.
Composer 2.10.3 fixes two more CVEs, including a Perforce command injection
Versions 2.10.2 and 2.10.3 fixed a run of CVEs, from path traversal through package bin paths to command injection through malicious Perforce URLs.
Laravel's summer advisories: CRLF injection, signed URL path confusion and a debug-page XSS
Three framework advisories landed this summer, including a High-severity CRLF injection in the default email validation rule.