Skip to content
Oday Bakkour
Back to Knowledge Hub
securitydevelopment

Daily Dev Stack Release Audit — July 27, 2026: Node.js, Redis, and Next.js Rush Out Critical Security Patches

Oday Bakkour profile photo
Oday Bakkour
14 min read
Share
Daily Dev Stack Release Audit — July 27, 2026: Node.js, Redis, and Next.js Rush Out Critical Security Patches

Three security stories dominate today's audit: Node.js pre-announced coordinated High-severity security releases across its 22.x, 24.x, and 26.x lines for July 27, Redis shipped a coordinated patch wave across seven version lines for a stream RESTORE use-after-free that can lead to remote code execution, and the Next.js team's July 2026 Security Release patched nine CVEs spanning DoS, SSRF, and cache-confusion bugs. Layer in Keycloak 26.7's four CVE fixes, Docker's BuildKit and Desktop patches, and shadcn/ui's credential-leak fix from earlier this month, and the message for engineering teams is consistent: patch before you ship anything new. Here is the full sweep across containers, identity, meta-frameworks, backend runtimes, UI systems, and data infrastructure.

Executive Summary

  • Node.js pre-announced coordinated security releases across the 22.x, 24.x, and 26.x lines for today, July 27, 2026, with High severity fixes; CVE IDs land with the patched builds.
  • Redis published a same-day patch wave — 8.8.1, 8.6.5, 8.4.5, 8.2.8, 7.4.10, 7.2.15, and 6.2.23 — fixing a stream RESTORE use-after-free that two consumers sharing a NACK could exploit toward RCE.
  • Next.js closed out its July 2026 Security Release (9 CVEs: DoS, SSRF, cache confusion, information disclosure) in v16.2.11/15.5.21, now superseded by the 16.2.12/15.5.22 patch builds.
  • Docker shipped Engine 29.6.2 (five BuildKit CVEs) and Desktop 4.83.0 (CVE-2026-8936, a VM panic via unbounded recursion in grpcfuse).
  • Keycloak 26.7.0 landed as a major feature release — Identity Brokering API v2, Admin API v2, SCIM preview, AuthZEN support — while closing four CVEs from the 26.6.x cycle.
  • Podman 6.0.2 is a bug-fix patch on top of the CNCF-org-move major (v6.0.0), which itself fixed CVE-2026-57231 (host env-var leakage via malformed image Env entries).
  • Clerk disclosed a critical CVE-2026-41248 (CVSS 9.1) middleware bypass affecting @clerk/nextjs, @clerk/nuxt, and @clerk/astro, already patched.
  • shadcn/ui 4.13.1 fixed three registry-related vulnerabilities: cross-origin credential leakage, path traversal, and CLI flag injection.
  • AWS CLI carries CVE-2026-13769 — world-readable credential files on Unix-like systems in v1 ≤1.44.77 and v2 ≤2.34.28.
  • Django 6.0.7 / 5.2.16 closed three Low-severity CVEs (cached cookie exposure, GDALRaster heap over-read, header injection via DomainNameValidator).
  • Elsewhere: Nuxt 4.5.0 (Vite 8, Rspack 2, SSR streaming), Astro 7.1.3, Vue 3.6.0-rc.2 (Vapor Mode), Prisma 7.9.0, pgvector 0.8.5, and Cloudflare's new Precursor bot-management engine all shipped meaningful, non-security updates.

Containers, Edge & Infrastructure

Docker

Docker Engine v29.6.2 (July 16) patches five BuildKit CVEs at once: CVE-2026-15793 (Git source checkout command injection), CVE-2026-15792 (frontend parameter panic), CVE-2026-15791 (LLB file-op directory-removal risk), CVE-2026-15789 (source-upload destination-validation bypass), and CVE-2026-15788 (WCOW cache-mount NTFS junction flaw). It also bumps containerd to v2.2.6 and Go to 1.26.5. Docker Compose v5.3.1 (July 7) is a dependency-hardening release, and Docker Desktop 4.83.0 (July 20) fixes CVE-2026-8936, a VM panic from unbounded recursion in the grpcfuse kernel module triggered by deeply nested directories on a bind mount.

bash.txt
# Verify patched Engine version
docker version --format '{{.Server.Version}}'
# Expect: 29.6.2 or later

Sources: Docker Engine 29 release notes · Docker Desktop release notes · docker/compose releases

Cloudflare

Cloudflare GA'd Precursor (July 13), a continuous, in-browser behavioral bot-defense engine replacing static challenge pages, alongside a new regionally tiered Workers Cache (July 6). Workers KV's legacy namespace API routes are deprecated as of July 15 and shut off October 15, 2026 — migrate to /accounts/{id}/storage/kv/namespaces/*. R2 Data Catalog picked up automatic manifest-file optimization and Iceberg snapshot expiration (July 13), and @cloudflare/workers-types v5 (July 3) is a breaking simplification for anyone pinning older runtime types.

Sources: Cloudflare changelog · Precursor announcement · Workers KV deprecation notice

Vercel

Vercel WAF for Blob entered beta (July 24) alongside Workflow steps supporting durations up to 30 minutes and Claude Opus 5 landing in AI Gateway with BYOK and automatic failover. Build logs now redact env vars flagged "Sensitive" that are 32+ characters (July 9). "Vercel Services" — multi-framework, multi-backend deployment (Go, Rails, FastAPI) in one project with Docker support — rolled out in late June.

Source: Vercel changelog

Kubernetes & Podman

Kubernetes is steady at v1.36.2 (June 9); v1.37.0 is scheduled for August 26, 2026. Podman v6.0.2 (July 22) is a bug-fix patch on the v6.0.0 major, which moved Podman's import path to go.podman.io/podman/v6 under a new CNCF-owned org and fixed CVE-2026-57231 — malformed Env entries in a malicious image (including via * glob) could leak host environment variables into containers.

Sources: Kubernetes releases · containers/podman releases

Cloud Platforms

AWS CLI carries CVE-2026-13769 (Security Bulletin 2026-049): credential and config files were written world-readable on Unix-like systems in CLI v1 ≤1.44.77 and v2 ≤2.34.28 — upgrade and re-check file permissions on any long-lived CI runners. Amazon Corretto shipped its July quarterly update (July 22: Corretto 26.0.2, 25.0.4, 21.0.12, 17.0.20, 11.0.32, 8u502). Railway shipped DNS logs and CLI-based Railway API queries (July 24). Render added managed OIDC support for Anthropic and OpenAI API auth, removing the need for long-lived API keys (July 24), plus OAuth support for Claude Code, Codex, and Cursor in its MCP server (July 22).

Sources: AWS Security Bulletin 2026-049 · Railway changelog · Render changelog

Identity & Authentication (IAM)

Keycloak

26.7.0 (July 9) is a major feature release: Identity Brokering API v2, a declarative Admin API v2, SCIM API in preview, simplified multi-cluster HA v2 (no external Infinispan requirement), AuthZEN authorization API support, and OpenID Shared Signals Framework (SSF) real-time security signals. It also closes four CVEs from the 26.6.x cycle: CVE-2026-9796 (admin-role-rename TOCTOU bypass), CVE-2026-9689 (OIDC HTTP Parameter Pollution), CVE-2026-9798 (CIBA brute-force bypass), and CVE-2026-11986 (FGAP v1 role-unassignment vulnerability).

Source: Keycloak 26.7.0 released

Authentik

2026.5.6 (July 22) is a stability release: fixed flow re-request/locale bugs, SCIM provider group-member removal, and added per-IP rate throttling. It sits atop a run of already-patched advisories worth confirming you're past: CVE-2026-49448 (auth bypass via empty POST to a Source stage), CVE-2026-25748 (forward-auth bypass via crafted cookie behind Traefik/Caddy), and CVE-2026-25227 (RCE via the property-mapping/expression-policy test endpoint).

Sources: Authentik releases · CVE-2026-49448

Clerk & Auth0

Clerk's most consequential recent item is CVE-2026-41248 (CVSS 9.1) — a middleware route-protection bypass in @clerk/nextjs, @clerk/nuxt, and @clerk/astro that let crafted requests skip auth gating entirely. It's fixed in @clerk/nextjs 5.7.6/6.39.2/7.2.1, @clerk/nuxt 1.13.28/2.2.2, and @clerk/astro 1.5.7/2.17.10/3.0.15 — audit your lockfile if you're anywhere near those version floors. On the feature side, Clerk shipped clerk mcp install (July 22) to register its MCP server across AI clients including Claude Code and Cursor in one command. Auth0 opened Anonymous Sessions in beta (July 20) for stateless unauthenticated-user state ahead of login.

bash.txt
# Check your Clerk Next.js version against the patched floor
npm ls @clerk/nextjs

Sources: Clerk changelog · CVE-2026-41248 writeup · Auth0 changelog

Better Auth & Auth.js

Better Auth v1.6.25 (July 23) is a bug-fix release (Apple OAuth PKCE, Google One Tap sign-up gating). More important for anyone still catching up: the coordinated "Security update: June 2026" disclosure covered 13 advisories, including CVE-2026-45337 (device-authorization session-binding flaw), CVE-2026-53514 (organization-invite email-match account takeover), and CVE-2026-53513 (critical SSRF in @better-auth/sso) — fixed in [email protected]+ and @better-auth/[email protected]+. Auth.js/NextAuth's latest stable is [email protected], a security patch that binds OAuth state/nonce/PKCE cookies to the originating provider and NFKC-normalizes email addresses before validation to block homoglyph bypasses.

Sources: Better Auth security update: June 2026 · next-auth releases

Meta-Frameworks & Core Web Standards

Next.js & React

Next.js's July 2026 Security Release (July 20) is the release to know about: nine CVEs across App Router DoS (CVE-2026-64641), a Middleware/Proxy bypass under Turbopack with single-locale i18n (CVE-2026-64642), SSRF via rewrites()/redirects() (CVE-2026-64645) and Server Actions on custom servers (CVE-2026-64649), plus Medium-severity DoS, cache-confusion, and endpoint-disclosure bugs. Fixed in 15.5.21/16.2.11, now superseded by the maintenance builds 16.2.12 and 15.5.22 (July 25). React shipped coordinated patches 19.2.8 / 19.1.9 / 19.0.8 (July 21) with RSC payload-decoding performance improvements — no security content.

bash.txt
npm install next@latest   # pulls 16.2.12 / patched line

Sources: Next.js July 2026 Security Release · Next.js security advisories · React releases

Nuxt & Vue.js

Nuxt 4.5.0 (July 18) is the biggest Nuxt release in a while: Vite 8 and Rspack 2 upgrades, experimental SSR streaming for better TTFB, a stable error-code system, and a new useLayout composable. Nuxt 3 reaches end-of-life July 31, 2026, and 3.21.9 is one of its last releases. Vue core is stable at 3.5.40 (July 16) with 3.6.0-rc.2 (July 22) rounding out Vapor Mode and an alien-signals-based reactivity rewrite ahead of the 3.6 release.

Sources: Nuxt releases · Vue core releases

SvelteKit & Svelte

Svelte 5.56.8 (July 24) fixes error-boundary hydration and <select> attribute-spreading edge cases. SvelteKit's v3 track hit 3.0.0-next.12 (July 24) with breaking type renames (PathnamePath, AssetAssetPath) and a new $app/manifest module for immutable assets and prerendered routes.

Sources: Svelte releases · SvelteKit releases

Astro

[email protected] (July 20) fixes excessive parallel image-optimization during astro build that could OOM CPU-limited containers. The 7.1.x line also picked up a cookie dependency bump, a new deferRender content-loader option, and CSP directive support. Two High-severity advisories affect the older 6.x line specifically and are worth checking if you haven't upgraded: CVE-2026-59731 (authorization bypass via decode-iteration mismatch, fixed 6.4.8) and CVE-2026-54299 (SSRF via Host-header manipulation, fixed 6.4.6).

Sources: Astro releases · Astro security advisories

Backend Frameworks & Runtimes

NestJS & Node.js

NestJS v11.1.28 (July 8) is a bug-fix release that also pulls @nestjs/platform-fastify up to Fastify 5.10.0 and bumps Multer to v2.2.0 for its security fixes. The bigger story is Node.js: the project pre-announced coordinated High-severity security releases across the 22.x, 24.x, and 26.x lines for today, July 27, 2026 — specific CVE IDs land with the patched builds, so treat this as an active watch item rather than a closed loop. Latest Current is v26.5.0 (July 8); latest LTS builds are v24.18.0 "Krypton" and v22.23.1 "Jod" (both June 23).

Sources: Node.js July 2026 security releases · NestJS v11.1.28

Fastify & Express

Fastify v5.10.0 (July 5) adds a log-controller layer and per-request performance work — no new CVEs, but it's worth confirming you're past v5.8.5 (April 14), which fixed CVE-2026-33806: a Content-Type header with a leading space could bypass body-schema validation entirely (CVSS 7.5, High). Express is quiet at v4.22.2 (May 11), a regression fix for array-notation query-string parsing.

bash.txt
curl -H "Content-Type: <space>application/json" ...
# Prior to Fastify 5.8.5, this bypassed schema.body validation

Sources: Fastify GHSA-247c-9743-5963 · Express releases

ElysiaJS & Hono

Hono v4.12.32 (July 24) hardens query/header/param parsing with Object.create(null) to reduce prototype-pollution surface, plus AWS Lambda JWT authorizer typings. ElysiaJS is quieter at 1.4.29 (June 16), a multipart/form-data parsing tweak — the stalest release among the runtimes tracked this cycle.

Sources: Hono releases · Elysia releases

Python Stack: FastAPI & Django

FastAPI 0.140.0 (July 24) reduces memory usage in dependency resolution — no security content. Django's monthly security cadence continued with 6.0.7 / 5.2.16 (July 7), closing three Low-severity CVEs: CVE-2026-48588 (cached Set-Cookie could leak private data across users sharing a cache), CVE-2026-53877 (heap buffer over-read in GDALRaster), and CVE-2026-53878 (header injection via DomainNameValidator accepting newline characters).

Sources: Django security releases · FastAPI releases

PHP Stack: Laravel

Laravel v13.22.0 (July 24) merged 21 PRs: a #[BindWhen()] attribute for conditional container binding, multi-queue support in queue:clear, and native PHP 8.4 optimizations for Str::ucfirst/Str::lcfirst. No CVEs in this release.

Source: Laravel v13.22.0

UI Systems, Styling & Motion

shadcn/ui & Radix UI

[email protected] (July 25) added a public addRegistryItems API for installing registry items without the CLI. More importantly, 4.13.1 (July 17) shipped three security fixes: dropped custom registry headers on cross-origin redirects (credential-leak fix), added file-path validation for registry items (path-traversal fix), and blocked flag injection from registry-supplied dependency strings. Base UI is now the default component base for new shadcn projects, replacing Radix. Radix itself hit [email protected] (July 24), reverting a change that had broken React Server Components compatibility.

Sources: shadcn/ui changelog · Radix release notes

Tailwind CSS & Material UI

Tailwind v4.3.3 (July 16) is bug-fix-only: --watch --poll[=ms] for unreliable filesystems, case-insensitive arbitrary hex-color matching, and a fix for Firefox stripping iframe:focus-visible outlines under Preflight. MUI's @mui/[email protected] (July 3) adds typed data-* attribute support on slotProps.

Sources: Tailwind CSS releases · MUI releases

Motion

[email protected] (late June) continues iterating on animateView, the View Transition API wrapper that graduated out of early access, adding automatic DOM-hierarchy layer grouping. Separately, Motion announced "Motion UI" (July 23), a new library of production-ready animated components. Watch for the typosquat package framer-motion-js (distinct from the legitimate framer-motion/motion packages), flagged as fully malicious with a CVSS 10.0 rating.

Sources: Motion changelog · Motion blog

PostgreSQL & pgvector

PostgreSQL's latest cumulative release is 18.4 / 17.10 / 16.14 / 15.18 / 14.23 (May 14), fixing 11 CVEs and 60+ bugs; PostgreSQL 19 Beta 2 followed on July 16. pgvector 0.8.5 (July 8) reduces memory usage for small-table IVFFlat index builds. If you're still on pgvector below 0.8.2, prioritize the upgrade — CVE-2026-3172 is a buffer overflow in parallel HNSW index builds (0.6.0–0.8.1) that can leak data from other relations or crash the server; mitigate in place with max_parallel_maintenance_workers = 0 if you can't upgrade immediately.

Sources: PostgreSQL 18.4 et al. released · pgvector CVE-2026-3172

Redis

Redis's July 23 coordinated patch wave — 8.8.1, 8.6.5, 8.4.5, 8.2.8, 7.4.10, 7.2.15, and 6.2.23 — fixes a stream RESTORE use-after-free where two consumers sharing the same NACK can corrupt memory toward remote code execution; the 8.x builds also patch RedisBloom/TDigest loader out-of-bounds issues. This follows a May 5 disclosure of five CVEs (CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, CVE-2026-23631) across RESTORE and Lua paths.

bash.txt
redis-cli INFO server | grep redis_version
# Compare against your line's patched floor above

Source: Redis security advisory blog

MongoDB, ClickHouse & DuckDB

MongoDB's latest stable patch is 8.3.7 (July 22) on the 8.3 series, which made the Cost-Based Ranker the default query planner and shipped $scoreFusion to GA. ClickHouse 26.7.1.1315 (July 22) follows the feature-dense 26.6 monthly release (hypothetical skip indexes, cascading refreshable materialized views). DuckDB is stable at 1.5.4 "Variegata" (June 17), fixing VARIANT-casting and window-self-join optimizer bugs plus an Arrow GeoArrow serialization memory leak.

Sources: MongoDB release notes · ClickHouse releases · DuckDB 1.5.4

Database Tools, ORMs & BaaS

Prisma & Drizzle

Prisma ORM v7.9.0 (July 21) adds shell tab-completion across bash/zsh/fish/PowerShell and an AI-agent skills catalog installed via prisma init, continuing the Rust-free Prisma 7 generation. Drizzle's stable npm channel sits at 0.45.x while the actively developed v1 track reached 1.0.0-rc.4 (June 27), fixing subquery field-type and driver-compatibility issues ahead of a stable v1.

Sources: Prisma changelog · Drizzle releases

Supabase & Firebase

Supabase deprecated Postgres extension version pinning (July 22, enforced August 5) and opened Supabase Pipelines — managed CDC from Postgres to BigQuery — in public alpha (July 21). Its self-hosted API gateway switches from Kong to Envoy by default the week of August 9. Firebase's CLI picked up studio:export for moving Firebase Studio projects to Antigravity, and Next.js next.config.ts/.mts support.

Sources: Supabase changelog · Firebase release notes

Background Jobs, Messaging & Task Queues

BullMQ, RabbitMQ & Kafka

BullMQ is shipping near-daily: core v5.81.2 (July 24) fixed connection-initialization failures, and the Python, Rust, and Elixir ports all saw releases within the same 48 hours. RabbitMQ 4.3.4 (July 23) is a maintenance release hardening quorum-queue metrics and Management UI CSP headers; the 4.2.x line's 4.2.9 (July 20) raises the minimum supported Erlang to 27.0. Apache Kafka is steady at 4.3.1 (June 25), a bugfix release most notable for closing a Kafka Streams RocksDB native-memory leak.

Sources: BullMQ releases · RabbitMQ release information · Kafka 4.3.1 announcement

Temporal

Temporal Server's latest is v1.31.2 (July 8, alongside v1.30.6). Operators running authorization with cross-cluster replication should confirm they're past CVE-2026-5724 (Moderate) — the frontend gRPC streaming interceptor chain omitted the authorization interceptor, allowing unauthenticated access to AdminService/StreamWorkflowReplicationMessages when ClaimMapper/Authorizer were configured; fixed in 1.28.4/1.29.6/1.30.4, with system.disableStreamingAuthorizer available as a stopgap.

Source: Temporal CVE-2026-5724 advisory

What to Do Today

If you patch nothing else this week: pull the Node.js 22.x/24.x/26.x security builds as soon as they land, confirm your Redis fleet is on 8.8.1/8.6.5/8.4.5/8.2.8/7.4.10/7.2.15/6.2.23 or later, and verify next is at 16.2.11+ or 15.5.21+. Everything else in this audit is either a feature release worth planning around (Nuxt 4.5, Keycloak 26.7, Vue 3.6-rc) or an older advisory worth a lockfile grep (Clerk, Better Auth, pgvector, Fastify, Astro 6.x).

Comments

Share your thoughts and join the conversation

Leave a Comment

Loading comments...
Add Oday Bakkour as a preferred source on Google
RELATED