Daily Dev Release Audit: Next.js CVE Patch, Postgres RCE Fix & Supabase Breaking Change

Today's sweep across containers, identity, meta-frameworks, backend runtimes, UI systems, databases, ORMs and messaging turned up one urgent security item, several breaking changes landing today, and a steady stream of framework maturity work. Below is the full technical breakdown, category by category, with links back to primary sources.
Executive Summary
- Supabase is removing the Management API logs.all endpoint today, September 23 — anything still calling it must move to the ClickHouse-backed logs endpoint before it breaks. (Supabase Changelog
- Next.js shipped a critical out-of-band security release for 16.3.6 and 15.5.26 — treat this as a same-day upgrade, not a backlog item. (Next.js Blog
- PostgreSQL 18.6/17.11/16.15/15.19/14.24 fixed CVE-2026-6471, a 12-year-old logical decoding flaw letting any role with REPLICATION run arbitrary code as the postgres OS user. (PostgreSQL Security
- Keycloak 26.7.3 closes out a run of CVEs in 26.7.2 — admin REST API secret leakage, fine-grained permission bypass, and a predictable account-linking hash. (Keycloak Releases
- Kubernetes CSI drivers for SMB and NFS both got path-traversal fixes (CVE-2026-3865, CVE-2026-3864), and ingress-nginx patched a comment-based config injection (CVE-2026-4342). (Kubernetes CVE Feed
- Docker Desktop 4.91.0 bundles Engine 29.8.0 and fixes CVE-2026-8936, a VM panic from unbounded recursion in the grpcfuse kernel module. (Docker Desktop Release Notes
- Redis 8.10.2 is stable; distros are backporting fixes for CVE-2026-66373, CVE-2026-72568 and CVE-2026-81934 into older 7.x lines. (Redis Releases
- Cloudflare Workers tripled the bundle-size cap to 64 MiB uncompressed and shipped Python 3.14 support and granular per-Worker permissions. (Cloudflare Changelog
- Prisma ORM is deep into its v8 release-candidate cycle (rc.8), with a @prisma/prisma7 compatibility shim so teams can migrate incrementally. (Prisma Changelog
- Vercel's AI Gateway added GPT-6 (Sol/Luna), Claude Opus 5.5 and Grok 4.7 in the same week, alongside Flat Rate CDN pricing and sub-second CLI deploys. (Vercel Changelog
Containers, Edge & Infrastructure
Docker
Docker Desktop 4.91.0 (September 14) pulls in Docker Engine v29.8.0, containerd v2.3.4, Docker Compose v5.1.4, Docker Agent v1.62.0 and NVIDIA Container Toolkit v1.19.1. The release fixes CVE-2026-8936 — a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container creates deeply nested directories on a bind-mounted host folder — plus Windows installer and PATH-handling bugs.
Separately, Compose v5.5.1 fixed docker compose watch syncing into symlinked directories and bake target-name collisions between services that differ only by - vs _. Full notes: Docker Desktop release notes · Compose releases.
docker desktop version
docker compose version
# Confirm Engine 29.8.0 and Compose v5.5.1+ before relying on the grpcfuse fixCloudflare (Workers, Pages, KV, R2)
Workers bundle size tripled from a compressed 10 MB cap to a flat 64 MiB uncompressed on every plan (Sept 4), removing a common pain point for AI/ML and bundler-heavy Workers. Python Workers gained 3.14 support for any Worker using compatibility date 2026-09-08 or later. On the access-control side, teams can now grant teammates, agents and CI/CD pipelines scoped access to specific Workers via four roles — Metadata Read-Only, Content Read-Only, Editor and Admin. Workflows created after Sept 10 on the Workers Paid plan now retain completed/errored instance state for 7 days by default, down from 30.
Source: Cloudflare Workers changelog · Granular Worker permissions · Python 3.14 for Workers
Vercel
Vercel's AI Gateway had a rapid-fire week: GPT-6 Sol and Luna (Sept 22), Claude Opus 5.5 with a 1M context window and adaptive thinking (Sept 22), and Grok 4.7 at a 40% launch discount (Sept 21) all landed within 48 hours. On the infra side, Flat Rate CDN pricing shipped for Pro teams (Sept 8), Secure Compute and Static IP builds now start 64% faster (6.7s → 2.4s), and Vercel Sandbox Drives — persistent, mountable storage up to 16 TiB — entered public beta (Sept 22).
Source: Vercel changelog.
Kubernetes & Podman
Three CVEs are worth patching this cycle: CVE-2026-3865 (path traversal via subDir in the Kubernetes CSI Driver for SMB, which can delete unintended directories on the SMB server), the equivalent CVE-2026-3864 in the CSI Driver for NFS, and CVE-2026-4342, a comment-based nginx configuration injection in ingress-nginx. None require a full cluster upgrade — patch the affected CSI drivers and ingress-nginx image tags directly.
Source: Kubernetes official CVE feed.
Identity & Authentication (IAM)
Keycloak
Keycloak 26.7.3 (Sept 16) follows a security-heavy 26.7.2 (Aug 25) that closed seven CVEs: CVE-2026-45292 (OpenTelemetry Java SDK unbounded memory allocation), CVE-2026-14613 (fine-grained admin permissions bypass), CVE-2026-59888/CVE-2026-59889 (jackson-databind upgrade), CVE-2026-15945 (group hierarchy search disclosure), CVE-2026-17048 (admin REST API leaking vault-resolved secrets), and CVE-2026-15571 (predictable account-linking hash). Any realm exposing the admin REST API or using vault-resolved secrets should prioritize this update.
Source: Keycloak 26.7.2 released.
Better Auth / Auth0 / Clerk
Better Auth shipped broader Cloudflare social-login support, schema validation on by default at init, and new password-compromise checks, alongside fixes for Auth0 domain normalization (a slow trailing-slash path), OAuth discovery failures that could take down the whole auth API, and per-instance OpenTelemetry span control. Auth0 made the Flexible Password Policy the default for new database connections (aligned with current NIST guidance) and added Google One Tap to Universal Login in early access. Clerk's WebAuthn/passkey support is now GA, supporting up to 10 passkeys per account with cross-device authentication.
// Better Auth: enable the new password-compromise check
export const auth = betterAuth({
emailAndPassword: {
enabled: true,
minPasswordLength: 12,
passwordCompromiseCheck: true, // new in Sept 2026 release
},
});Source: Better Auth changelog · Auth0 changelog.
Meta-Frameworks & Core Web Standards
Next.js & React
Vercel pushed a critical out-of-band security release for Next.js 16.3.6 and 15.5.26 on September 22 — apply it immediately rather than folding it into a routine bump. Alongside that, recent patch releases backported fixes for next/image (skipping and rejecting 0-byte disk-cache entries), standalone-output builds under adapters (emitting whole-app server NFTs), CSP nonces on loading/template script tags, and use cache prerender-signal retention. On canary, Turbopack chunking continues to shrink cache size and speed up navigation.
npm install [email protected]
# or, on the 15.x line:
npm install [email protected]Source: Next.js blog.
SvelteKit & Svelte
Svelte 5.57 added new SvelteMap methods and quality-of-life fixes, while SvelteKit 3 moved to Release Candidate with stronger single-flight mutation handling, new adapter hooks for Vite dev/preview, and refreshed manifest and instrumentation APIs — note the breaking changes to env-var loading and the adapter instrumentation API. The sv CLI replaced its old mcp add-on with a new ai-tools add-on, and sv@next now ships a task-based migration path to SvelteKit 3 for existing apps. The stable 2.x line kept shipping patches (2.70.1–2.70.3) in parallel.
Source: What's new in Svelte: September 2026.
Backend Frameworks & Runtimes
Node.js
Node.js 26.8.2 landed September 9. It's a routine point release on the current line; no new CVEs were disclosed alongside it, though earlier 2026 security releases across the 20.x/22.x/24.x/25.x lines fixed a V8 HashDoS issue (CVE-2026-21717), an fs.realpathSync.native() permission-check bypass (CVE-2026-21715), and an incomplete chmod/chown patch (CVE-2026-21716) worth confirming are applied on any LTS line still in production.
Source: Node.js security releases.
ElysiaJS & Hono (Bun/Edge runtimes)
Bun v1.4.2 fixed two v1.4.1 regressions — a bun build rename bug that broke Elysia apps, and an AsyncLocalStorage memory leak — plus worker_threads ordering, GC/JIT crashes, CMYK JPEG decoding, and a bun install lockfile panic. ElysiaJS itself is on 1.4.30 (Aug 26) and now in maintenance mode: the 1.4.x line will only receive security patches while the team focuses on Elysia 2.
Source: Bun v1.4.2 blog post · Elysia releases.
NestJS & Fastify
Fastify 5.12.4 shipped September 11 as a routine patch. On the Nest side, @nestjs/platform-fastify reached 12.0.3, part of the NestJS 12 line's push toward ESM-ready packages, first-class Standard Schema support for validation and serialization, a rebuilt CLI, and native observability via the new @nestjs/observe SDK.
Python Stack: FastAPI & Django
Django 6.1.1 landed September 2 as a maintenance patch two weeks after the 6.1 feature branch. FastAPI's most recent tagged release remains 0.141.1 from late July — nothing new shipped in September, which is itself worth noting if you're tracking cadence for a dependency-freshness dashboard.
Source: FastAPI release notes.
PHP Stack: Laravel
Laravel shipped two minor releases in quick succession: 13.31 (Sept 9) added Queue::totalSize() to count every job on a connection, a JobInterrupted event, and chaperone support for BelongsToMany pivot models; 13.32 (Sept 16) followed with a Mercure broadcast driver, Storage::copyToDisk()/moveToDisk(), and enum support for queue pause/resume.
composer require laravel/framework:^13.32Source: Laravel changelog.
UI Systems, Styling & Motion
shadcn/ui & Tailwind CSS
September's shadcn/ui changelog introduces a cn utility migration: existing projects using lib/utils.ts keep working unchanged, but new component installs place cn alongside it, and a new CLI command rewrites imports and collapses twMerge(clsx(...)) call sites for Tailwind CSS v4 projects, removing clsx and tailwind-merge as separate dependencies once nothing else references them.
npx shadcn migrate cnSource: shadcn/ui September changelog.
Databases, Caching & Vector Search
PostgreSQL & PgVector
PostgreSQL 18.6, 17.11, 16.15, 15.19 and 14.24 (Aug 13) fixed 28 security issues and 110+ bugs. The headline is CVE-2026-6471 (CVSS 7.2): any role with the REPLICATION attribute could run arbitrary code as the OS user running the server, a flaw present since logical decoding was introduced in Postgres 9.4 back in 2014. The fix adds an output_plugin_libraries server parameter that allow-lists which libraries may load as logical decoding output plugins, defaulting to pgoutput and test_decoding. Postgres 14 goes end-of-life on November 12, 2026 — plan the jump to 15+ now if you haven't.
-- After upgrading, confirm the allow-list is active:
SHOW output_plugin_libraries;
-- default: 'pgoutput, test_decoding'Source: PostgreSQL security advisory · The Hacker News coverage.
Redis
Redis Open Source's stable line moved to 8.10.2 (Sept 17). Downstream, Oracle Linux 9 rebased its Redis package to 7.2.16 (Sept 9) to backport fixes for CVE-2026-66373, CVE-2026-72568 and CVE-2026-81934 — a reminder that distro-packaged Redis often lags the upstream fix by weeks, so check your base image's Redis version explicitly rather than trusting a `latest` tag.
Source: Redis releases on GitHub.
ClickHouse & DuckDB (Analytics/OLAP)
ClickHouse 26.8 LTS (v26.8.2.7-lts, Sept 1) introduced background queries, pipelined SQL execution, new Japanese/Chinese tokenizers for the text index, expanded data-lake integrations, and faster Parquet, aggregation and join performance. Custom HTTP handlers also shipped in the same cycle.
Source: ClickHouse September newsletter.
Database Tools, ORMs & BaaS
Prisma ORM
Prisma ORM v8.0.0-rc.8 is out, paired with a new @prisma/prisma7 compatibility package that keeps a prisma7 CLI alias available so teams can upgrade incrementally instead of all at once. Prisma 8 removes the flat prisma-next.config.ts shape in favor of prisma.config.ts using definePrismaConfig exclusively, consolidates commands under unified paths (db migrate, contract format, orm init), and renames pagination methods: .take(n)/.skip(n) become .limit(n)/.offset(n). The toolchain also moved to @prisma/[email protected], which adds a Markdown output format to every CLI command.
// Prisma 8: prisma.config.ts is now the only accepted config shape
import { definePrismaConfig } from '@prisma/config';
export default definePrismaConfig({
schema: 'prisma/schema.prisma',
});Source: Prisma changelog.
Drizzle ORM
Drizzle's release cadence was quiet this week; the notable item is updated neon-http driver compatibility for @neondatabase/serverless 1.0.0, with drizzle-orm supporting both pre-1.0 and 1.0+ versions of that package simultaneously so existing Neon integrations don't break on the serverless driver's major bump.
Source: Drizzle ORM latest releases.
Supabase & Firebase
The one true breaking change firing today: Supabase removes the Management API's logs.all endpoint on September 23. Any script or dashboard still calling it must switch to the new ClickHouse-backed logs endpoint, which only accepts ClickHouse SQL — plain SQL or the old query shape will fail outright. Elsewhere, Postgres Changes subscriptions can now combine filters with AND and match on like, ilike and is, returning only the columns you request instead of the full row; and supabase-js, Swift, Flutter and Python clients now propagate W3C Trace Context so a client-side trace and its matching Supabase log share one trace_id.
-- Old (removed today): Management API logs.all endpoint
-- New: ClickHouse-backed logs endpoint, ClickHouse SQL only
SELECT event_message, timestamp
FROM edge_logs
WHERE timestamp > now() - INTERVAL 1 HOUR
ORDER BY timestamp DESC
LIMIT 100;Source: Supabase changelog.
Background Jobs, Messaging & Task Queues
Apache Kafka's stable line remains 4.2.0 (Feb 16) with 4.3.0 having shipped in May — no new tagged release this week. Temporal and BullMQ likewise had no dated release announcements surface in today's sweep; treat both as steady-state and revisit tomorrow. If your pipeline depends on any of the three, this is a good week to instead audit consumer-lag alerts and dead-letter queue depth rather than chase a version bump that isn't there yet.
What To Patch Today
- Ship the Next.js 16.3.6 / 15.5.26 security release before anything else on this list.
- Confirm Postgres is on 18.6/17.11/16.15/15.19/14.24 or later — CVE-2026-6471 allows RCE via replication roles.
- Update Keycloak to 26.7.3 if you're exposing the admin REST API or using vault-resolved secrets.
- Patch the Kubernetes CSI drivers for SMB/NFS and ingress-nginx for the three CVEs above.
- If you call Supabase's Management API logs.all, migrate to the ClickHouse-backed logs endpoint before it disappears today.
That's the full stack sweep for today. Check back tomorrow for the next release audit.
Comments
Share your thoughts and join the conversation
