Skip to content
Oday Bakkour
Back to Knowledge Hub

Dev Release Radar: Next.js 16.3.7 Due, Docker 4.93 Out

Oday Bakkour profile photo
Oday Bakkour
3 min read
Share

Today's audit is dominated by what is coming: Next.js has pre-announced a nine-vulnerability security release for tomorrow, September 30. Meanwhile Docker Desktop 4.93.0 shipped a host-path exposure fix, Keycloak's 26.7.4 security batch is still the one to prioritise for IAM teams, and PostgreSQL 19 Beta 4 pruned several headline features. Node.js had no new security release in this window.

Executive Summary

Next.js: Plan Tomorrow's Upgrade Now

The Next.js team gave advance notice of a nine-vulnerability release due September 30, 2026. Full advisories ship with the patch, so details are not public yet. If you have not already applied the September 22 out-of-band update, do so first: it fixes a critical RCE in the Node.js ImageResponse implementation (GHSA-vcvr-r3jv-pc5j), affecting versions >=16.2.0 <16.3.6. Edge ImageResponse is not affected.

Terminal
# Now: minimum safe baseline
npm install [email protected]   # or [email protected]

# After the Sept 30 advisories are published
npm install [email protected]   # or [email protected]

Docker Desktop 4.93.0

Released September 28, 4.93.0 fixes a vulnerability that let VM-side code request Unix socket port forwards, potentially exposing arbitrary host paths (no CVE listed). It also fixes Enhanced Container Isolation not being enforced on an engine left running while another was in use. The bundled Linux kernel moves to 7.0.14, which resolves MongoDB 8 container startup failures. Components: Engine 29.8.1, Docker Agent 1.141.0, Offload 0.6.33. Windows fixes include MSI group membership for docker-users and startup crashes from a UTF-8 BOM in config files.

Terminal
docker version --format '{{.Server.Version}}'   # expect 29.8.1
docker context ls

Keycloak 26.7.4: Six Security Fixes

The 26.7.4 release (September 16, also covered in Self-Hosted Weekly) is worth confirming you have deployed. The most serious issue, CVE-2026-17526, lets a user holding the impersonation role escalate to realm administrator, which matters because support roles are commonly delegated that permission.

  • CVE-2026-79651: unauthenticated denial of service via unbounded locale caching
  • CVE-2026-74909: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher
  • CVE-2026-19607: username takeover leading to account lockout
  • CVE-2026-18212: SAML redirect DEFLATE helpers exposed native zlib state
  • CVE-2026-90997: MySQL/MariaDB row-count default allowed replay of stateless artifacts

The release also upgrades Quarkus to 3.33.3.2 and fixes a performance regression from 26.6.2. Read the migration guide before upgrading.

PostgreSQL 19 Beta 4

The fourth beta reverted SQL/PGQ property graph queries, online enabling/disabling of data checksums and temporal updates/deletes via FOR PORTION OF so they can target a later major release. A release candidate is expected in early October, with GA possible later that month. If you were testing those features, pin your plans accordingly.

Valkey 9.2 RC1 (Redis-Compatible Caching)

9.2.0-rc1 adds opt-in forkless RDB snapshots (a background thread and iterator replace the fork child, see this walkthrough) and named, reusable ACL roles managed with ACL SETROLE/DELROLE/GETROLE/ROLES. It is a release candidate, so test in staging only.

valkey.conf
forkless-infrastructure-enabled yes
bgsave-default-method forkless

Node.js: No New Security Release

The Node.js vulnerability blog lists its latest security release on July 29, 2026, so there is nothing new to action this cycle.

Action Checklist

  1. Ensure Next.js is at 16.3.6 / 15.5.26 today; schedule 16.3.7 / 15.5.27 for September 30.
  2. Upgrade Keycloak to 26.7.4 and audit who holds the impersonation role.
  3. Update Docker Desktop to 4.93.0 on developer machines.
  4. Hold off on relying on PostgreSQL 19 beta-only features that were reverted.
Add Oday Bakkour as a preferred source on Google

Comments

Share your thoughts and join the conversation

Leave a Comment

Loading comments...
RELATED