Dev Release Radar: Next.js 16.3.7 Due, Docker 4.93 Out
Today's audit is dominated by what is coming: Next.js has pre-announced a nine-vulnerability security release for tomorrow, September 30. Meanwhile Docker Desktop 4.93.0 shipped a host-path exposure fix, Keycloak's 26.7.4 security batch is still the one to prioritise for IAM teams, and PostgreSQL 19 Beta 4 pruned several headline features. Node.js had no new security release in this window.
Executive Summary
- Next.js: a scheduled security release lands September 30 (16.3.7 and 15.5.27) covering 1 critical, 2 high, 5 medium and 1 low vulnerabilities.
- Docker Desktop 4.93.0: fixes a VM-side Unix socket port-forward flaw and an Enhanced Container Isolation enforcement gap; bundles Engine 29.8.1.
- Keycloak 26.7.4: six CVEs, including an impersonation-to-realm-admin escalation (CVE-2026-17526).
- PostgreSQL 19 Beta 4: released September 24 with SQL/PGQ, online checksum toggling and FOR PORTION OF reverted; RC expected early October.
- Valkey 9.2 RC1: opt-in forkless RDB snapshots and named ACL roles.
Next.js: Plan Tomorrow's Upgrade Now
The Next.js team gave advance notice of a nine-vulnerability release due September 30, 2026. Full advisories ship with the patch, so details are not public yet. If you have not already applied the September 22 out-of-band update, do so first: it fixes a critical RCE in the Node.js ImageResponse implementation (GHSA-vcvr-r3jv-pc5j), affecting versions >=16.2.0 <16.3.6. Edge ImageResponse is not affected.
# Now: minimum safe baseline
npm install [email protected] # or [email protected]
# After the Sept 30 advisories are published
npm install [email protected] # or [email protected]Docker Desktop 4.93.0
Released September 28, 4.93.0 fixes a vulnerability that let VM-side code request Unix socket port forwards, potentially exposing arbitrary host paths (no CVE listed). It also fixes Enhanced Container Isolation not being enforced on an engine left running while another was in use. The bundled Linux kernel moves to 7.0.14, which resolves MongoDB 8 container startup failures. Components: Engine 29.8.1, Docker Agent 1.141.0, Offload 0.6.33. Windows fixes include MSI group membership for docker-users and startup crashes from a UTF-8 BOM in config files.
docker version --format '{{.Server.Version}}' # expect 29.8.1
docker context lsKeycloak 26.7.4: Six Security Fixes
The 26.7.4 release (September 16, also covered in Self-Hosted Weekly) is worth confirming you have deployed. The most serious issue, CVE-2026-17526, lets a user holding the impersonation role escalate to realm administrator, which matters because support roles are commonly delegated that permission.
- CVE-2026-79651: unauthenticated denial of service via unbounded locale caching
- CVE-2026-74909: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher
- CVE-2026-19607: username takeover leading to account lockout
- CVE-2026-18212: SAML redirect DEFLATE helpers exposed native zlib state
- CVE-2026-90997: MySQL/MariaDB row-count default allowed replay of stateless artifacts
The release also upgrades Quarkus to 3.33.3.2 and fixes a performance regression from 26.6.2. Read the migration guide before upgrading.
PostgreSQL 19 Beta 4
The fourth beta reverted SQL/PGQ property graph queries, online enabling/disabling of data checksums and temporal updates/deletes via FOR PORTION OF so they can target a later major release. A release candidate is expected in early October, with GA possible later that month. If you were testing those features, pin your plans accordingly.
Valkey 9.2 RC1 (Redis-Compatible Caching)
9.2.0-rc1 adds opt-in forkless RDB snapshots (a background thread and iterator replace the fork child, see this walkthrough) and named, reusable ACL roles managed with ACL SETROLE/DELROLE/GETROLE/ROLES. It is a release candidate, so test in staging only.
forkless-infrastructure-enabled yes
bgsave-default-method forklessNode.js: No New Security Release
The Node.js vulnerability blog lists its latest security release on July 29, 2026, so there is nothing new to action this cycle.
Action Checklist
- Ensure Next.js is at 16.3.6 / 15.5.26 today; schedule 16.3.7 / 15.5.27 for September 30.
- Upgrade Keycloak to 26.7.4 and audit who holds the impersonation role.
- Update Docker Desktop to 4.93.0 on developer machines.
- Hold off on relying on PostgreSQL 19 beta-only features that were reverted.
Comments
Share your thoughts and join the conversation

