Dev Release Radar — September 28, 2026: Next.js Patches a Critical next/og RCE as MongoDB Closes a Critical Auth Bypass

Today's audit turned up a critical out-of-band security release from Next.js, a critical authentication-bypass advisory for MongoDB, and a dense band of CVE patches across containers, backend frameworks, and messaging systems — alongside routine feature releases across the React, Astro, and Motion ecosystems.
Executive Summary
- Next.js shipped an out-of-band critical-severity fix for a remote code execution flaw in the Node.js
next/og(ImageResponse) implementation — 16.3.6 and 15.5.26 (GHSA-vcvr-r3jv-pc5j); a further release fixing nine more vulnerabilities is scheduled for September 30. - MongoDB disclosed CVE-2026-82067 (CVSS 9.2, critical) — a config-validation bug that can leave authorization disabled at startup despite
security.authorization: true— fixed in 7.0.41 / 8.0.30 / 8.3.9, alongside eight more CVEs in the same disclosure batch. - Docker Engine 29.8.1 bumps bundled containerd to v2.3.5 to close CVE-2026-53495, plus fixes for dangling images under the containerd image store and a
GET /networks500 error. - Podman 6.1.2 patches CVE-2025-11395: crafted layer tarballs via
podman loador crafted symlinks viapodman volume importcould overwrite host files outside the extraction directory. - Redis shipped security releases 8.10.2 / 8.8.3 / 8.6.7 / 8.2.10 fixing an ACL key-permission bypass in
SORT,GEORADIUS, andXREAD/XREADGROUP, on top of the disputed-then-confirmed CVE-2026-81934 TLS use-after-free (revised to CVSS 7.5, high). - Laravel Framework patched CVE-2026-48019 (CVSS 8.9), an unauthenticated CRLF injection in email validation that could forge mail headers, fixed in
12.60.0and13.10.0. - NestJS 11.2.6 fixes CVE-2026-88932 by upgrading the bundled
multerdependency; separately, NestJS 12.1.0 adds built-in cookie support and CSRF protection. - Express 4.22.3 fixes CVE-2026-4867 by updating
path-to-regexp, and Fastify (5.12.5) and Elysia (1.4.30) both shipped security-only releases this week. - Apache Kafka disclosed CVE-2026-35554 (CVSS 8.7), a producer buffer-pool race condition that can corrupt or misroute messages with no error surfaced; fixed in
3.9.2 / 4.0.2 / 4.1.2. - Keycloak published GHSA-xpwp-2pcm-8xq3 (high), a replay-protection bypass via database-driver semantics mismatch, and Okta/Auth0 disclosed a combined eight-CVE advisory batch on September 8.
- RabbitMQ published four new advisories on September 18 covering OAuth/STOMP token-expiry handling and MQTT memory-exhaustion DoS, alongside the routine
4.3.6maintenance release. - React 19.3 stabilized
<ViewTransition>and Fragment refs; Kubernetes v1.37 ("Garhwal") brought DRA Extended Resources to GA; and shadcn/ui introduced a standalonecnpackage to replace the copy-pasted utils helper.
Containers, Edge & Infrastructure
Docker Engine 29.8.1 (September 15) bumps the bundled static containerd binaries to v2.3.5, closing CVE-2026-53495, and fixes docker load leaving dangling images under the containerd image store, a 500 error on GET /networks with an invalid type filter, and Windows hard-link preservation on commit. It follows the earlier 29.4.2/29.4.3 hardening against CVE-2026-31431 ("Copy Fail"), a container-escape/privilege-escalation bug via the AF_ALG kernel crypto API, which moved from a seccomp block to AppArmor/SELinux LSM-layer rules.
Podman 6.1.2 (September 15–16) is a security release fixing CVE-2025-11395: crafted layer tarballs via podman load or crafted symlinks via podman volume import could write files outside the intended extraction directory on the host. It also addresses CVE-2026-79699 and CVE-2026-79705 and bumps bundled Buildah to v1.45.1.
Kubernetes v1.37 ("Garhwal"), released August 26 with a release event held September 23, ships 67 enhancements — 16 stable, 23 beta, 27 alpha. Notably, DRA Extended Resource support reaches GA, new emptyDir permission-mode and bind-mount storage-security options land, the Metrics API graduates to GA, and HPA scale-to-zero enters beta.
Cloudflare shipped a busy September for Workers: Worker Previews (Sept 22) give every PR its own isolated, production-like preview environment; granular Worker permissions (Sept 15) let teammates, agents, and CI/CD get scoped access instead of account-wide; and the uncompressed Worker bundle size limit rose to 64 MiB on all plans. Note also that Workflows created on or after Sept 10 on the Workers Paid plan now retain completed/errored instance state for only 7 days by default, down from 30.
Identity & Authentication (IAM)
Keycloak published GHSA-xpwp-2pcm-8xq3 (high, disclosed Sept 16): a replay-protection bypass stemming from a database-driver semantics mismatch that can lead to unauthorized access. The latest numbered release remains 26.7.0 from July; no new version shipped this week, only the advisory.
Okta and Auth0 disclosed a combined advisory batch on September 8. Okta's four CVEs (CVE-2026-78545, CVE-2026-78550, CVE-2026-78623, CVE-2026-78622) span input sanitization in Access Gateway, the management console, SAML assertion handling, and the Okta Verify for Windows uninstaller. Auth0's four (CVE-2026-85983, CVE-2026-85982, CVE-2026-85981, CVE-2026-84685) include a local privilege escalation and stored XSS in the AD/LDAP Connector, an unauthenticated localhost admin panel exposure, and a cache-isolation flaw in the react-native-auth0 SDK. See the Okta trust advisories page for both brands.
Better Auth shipped v1.7.6 (Sept 24), rejecting passwords over the configured max length before hashing (returned as PASSWORD_TOO_LONG), fixing React hydration mismatches in session/plugin auth queries, and restoring OAuth Proxy social-account linking. Authentik 2026.8.3 (Sept 17) fixed an LDAP memory leak and OAuth token exchange when a signing key is absent, among 18 patches. Clerk reached GA on Client ID Metadata Documents for MCP-style OAuth clients and now supports multiple enterprise SAML/OIDC connections per organization.
Meta-Frameworks & Core Web Standards
Next.js is the story of the week. The out-of-band 16.3.6 / 15.5.26 release (Sept 22) fixes GHSA-vcvr-r3jv-pc5j, a critical-severity RCE in the Node.js next/og (ImageResponse) implementation caused by improper SVG escaping in the upstream Satori dependency. It affects Next.js >=16.2.0 <16.3.6; the Edge ImageResponse implementation is not affected. A further release fixing nine more vulnerabilities (1 critical, 2 high, 5 medium, 1 low) is scheduled for September 30.
npm install [email protected] # for the 16.3 line
npm install [email protected] # for 15.5 (hardening only)React 19.3 (Sept 9) stabilized the <ViewTransition> component and addTransitionType API, and stabilized Fragment refs (yielding a FragmentInstance with focus()/blur()/observeUsing()), plus a new browser() API to opt components out of SSR. No breaking changes.
Astro shipped a breaking change in @astrojs/react 7.0.0 (Sept 22): it upgrades to @vitejs/plugin-react v6, switches JSX processing to Oxc, and removes the Babel integration option entirely — custom Babel transforms need to migrate to @rolldown/plugin-babel. Elsewhere, SvelteKit continues its march toward 3.0 through nightly @next preprelease builds, Svelte 5.57.1 shipped patch fixes, and Vue 3.6 remains in release-candidate (3.6.0-rc.9). Nuxt core has had no release since August 5; the only fresh Nuxt-ecosystem item this week is Nuxt UI 4.11.2.
Backend Frameworks & Runtimes
Laravel Framework patched CVE-2026-48019 (CVSS 8.9), an unauthenticated CRLF injection in Laravel's email validation — interacting with Symfony Mailer/Mime — that let attackers forge mail headers or recipients through registration, password-reset, or newsletter forms. Fixed in 12.60.0 and 13.10.0; the framework's rapid feature cadence continued right up to v13.33.0 (Sept 22), which adds an opt-out from killing workers on job timeout and a new Storage::copyToDisk() helper.
NestJS 11.2.6 fixes CVE-2026-88932 (GHSA-3pph-fpjx-jg34) by upgrading the bundled multer dependency and correcting Express error mapping so unexpected upload fields return 400 instead of 500. The newer v12.1.0 line adds built-in, adapter-agnostic cookie support and CSRF protection with security headers out of the box.
Express 4.22.3 fixes CVE-2026-4867 by updating path-to-regexp to 0.1.13. Fastify 5.12.5 and Elysia 1.4.30 both shipped security-only maintenance releases this week — Elysia's maintainers confirmed active feature work has moved to the Elysia 2 branch, with 1.4.x now receiving patches only. Hono 4.13.9 fixed JSX Suspense and Lambda binary content-type handling, following an XSS fix in 4.13.7 that ensures plain-string JSX children are properly escaped.
Node.js 22.23.3 (LTS) and 26.10.0 (Current) shipped routine updates — root-certificate and ICU bumps, and new crypto.parsePKCS12() support respectively — with no new security release since July 29. Django's most recent security release (6.0.8/5.2.17, Aug 4) remains the latest word; nothing new shipped for Django or FastAPI this week.
UI Systems, Styling & Motion
Motion (formerly Framer Motion) was the most active library in this category: 13.4.4 (Sept 25) shrank the scroll bundle by 44% and sped up scroll callbacks by 50%, while 13.4.0 (Sept 14) added AnimateView, built directly on React 19.3's <ViewTransition>.
shadcn/ui CLI 4.21.0 introduced a standalone cn package — a drop-in twMerge(clsx(...)) replacement — replacing the copy-pasted lib/utils.ts helper, with a shadcn migrate cn codemod for existing projects. Radix UI Primitives, Tailwind CSS, and Material UI have all been quiet: their most recent releases land in July, July, and late August respectively, with nothing new this week.
Databases, Caching & Vector Search
MongoDB disclosed a nine-CVE batch on September 8, led by CVE-2026-82067 (CVSS 9.2, critical): improper case-sensitivity handling in configuration validation can leave authorization disabled at startup even with security.authorization: true set, letting an unauthenticated network attacker perform arbitrary admin operations. Fixed in 7.0.41 / 8.0.30 / 8.3.9. The batch also includes an unauthenticated mongos DoS (CVE-2026-82075) and an aggregation authorization bug (CVE-2026-82074).
Redis shipped security releases 8.10.2 / 8.8.3 / 8.6.7 / 8.2.10 fixing an ACL key-permission bypass in SORT, GEORADIUS/GEORADIUSBYMEMBER, and XREAD/XREADGROUP — where the keys validated by ACL could differ from the keys actually accessed — plus a cluster-bus authentication gap. This follows CVE-2026-81934, a TLS use-after-free Redis initially scored as CVSS 9.8 but revised to 7.5 after Redis disputed the required attack surface.
PostgreSQL and pgvector have had no new release in the last week; the most recent cumulative security release (18.6 / 17.11 / 16.15 / 15.19 / 14.24) from August 13 fixed 28 CVEs. ClickHouse cut fresh 26.9.4.3-stable and 26.8.13.2-lts point releases on Sept 27 — note a widely-circulated "CVE-2026-51992" SQL-injection claim for ClickHouse could not be verified against the project's own security changelog and remains an unreviewed, unconfirmed advisory. DuckDB's latest release remains 1.5.5 from July.
Database Tools, ORMs & BaaS
Prisma ORM continued its 8.0.0 release-candidate track with rc.12 (Sept 24), which drops the NEXT_ infix from CLI environment variables (PRISMA_NEXT_DISABLE_TELEMETRY → PRISMA_DISABLE_TELEMETRY); Prisma 8 final is expected in 4–8 weeks. Drizzle ORM 0.45.3 (Sept 21) adds a new Netlify DB driver, built with the Netlify team.
Supabase CLI 2.118.0 (Sept 25) adds a new supabase pull command that orchestrates a complete local setup from a remote project, plus native type generation without Docker. Firebase CLI 15.30.2 improved prompts for Cloud Functions secrets; separately, Firebase Remote Config moved to usage-based pricing on September 1, with a no-cost tier up to 100,000 daily fetches on Spark.
Background Jobs, Messaging & Task Queues
RabbitMQ published four new security advisories on September 18: an OAuth-authorized queue access issue where STOMP consumers retain access past JWT expiration (GHSA-j6hc-926v-qwq2), and an MQTT retained-message store with no size or count limits, enabling memory-exhaustion DoS. The 4.3.6 maintenance release (Sept 14) separately fixed exchange-deletion and quorum-queue membership reconciliation bugs.
Apache Kafka carries CVE-2026-35554 (CVSS 8.7): a race condition in the Java producer's buffer-pool management where a batch expiring via delivery.timeout.ms while a request is in flight can have its buffer reused by a later batch, corrupting or silently misrouting messages with no error to the producer. Fixed in 3.9.2 / 4.0.2 / 4.1.2.
Temporal Server 1.32.0 (Sept 19) graduates Standalone Activities to GA with operator APIs and batch operations, and adds Serverless Workers support via AgentCore Runtime. BullMQ 6.3.9 (Sept 25) improves backend-specific connection-option inference as the project rolls out an experimental Postgres backend alongside its existing Redis backend.
Comments
Share your thoughts and join the conversation
