Dev Stack Release Audit: Next.js 16.3.8 SSRF Fix, Keycloak 26.7.4 and PostgreSQL Security Patches

Executive Summary
- Next.js (high severity): 16.3.8 fixes a server-side request forgery in Image Optimization (GHSA-cjq9-62q9-8jv4) plus five medium and one low advisory. 15.5.27 backports three of the medium fixes.
- Keycloak: 26.7.4 closes six CVEs, including an impersonation-to-realm-admin escalation (CVE-2026-17526) and an unauthenticated denial of service.
- PostgreSQL: the latest security release (18.6, 17.11, 16.15, 15.19, 14.24) lists several CVSS 8.8 issues in pg_dump, psql and the core server.
- Node.js: 26.10.0 (Current), 24.21.0 and 22.23.3 (LTS) are the newest builds, and Node.js 26 is due to enter LTS this month.
Next.js 16.3.8 and 15.5.27: SSRF and Cache Fixes
The v16.3.8 release (September 30) is a security-focused release. Highlights:
- High: GHSA-cjq9-62q9-8jv4, SSRF in Image Optimization.
- Medium: GHSA-4jqv-mc3x-m676 and GHSA-mcj8-r9mp-w47p, cache poisoning of SSG/ISR pages in self-hosted deployments, including cross-user content substitution and persistent denial of service.
- Medium: GHSA-f87g-xv8r-7p7x, information disclosure in App Router metadata image routes via a dynamicParams bypass.
- Medium: GHSA-3w37-wq28-93x7 (Draft Mode content leaking through a pending
use cachefill) and GHSA-h694-7cp9-m8p3 (cache leak across root param values in nesteduse cache). - Low: GHSA-39w2-rjm5-chcv, information disclosure in the dev server's Model Context Protocol endpoint.
The v15.5.27 release backports the metadata-route and both cache-poisoning fixes for the 15.x line. Teams still on 16.3.6 or 15.5.26 (the RCE fix from September 22) should upgrade again.
npm install [email protected] react@latest react-dom@latest
# 15.x line
npm install [email protected]Until you upgrade, restrict image optimization to known hosts:
// next.config.js
module.exports = {
images: {
remotePatterns: [{ protocol: 'https', hostname: 'cdn.example.com' }],
},
}Keycloak 26.7.4: Six CVEs Fixed
The Keycloak 26.7.4 announcement (September 16) lists:
- CVE-2026-17526: the impersonation role can escalate to realm administrator.
- CVE-2026-79651: unauthenticated denial of service via unbounded locale caching.
- CVE-2026-19607: username takeover that locks out the victim.
- CVE-2026-74909: a percent-encoded semicolon bypasses matrix parameter stripping.
- CVE-2026-90997: default MySQL/MariaDB row counts let stateless replay gates accept reused artifacts.
- CVE-2026-18212: the SAML redirect DEFLATE helper leaks native zlib state.
The release also moves to Quarkus 3.33.3.2 and fixes a performance regression from 26.6.2. Review the migration guide before upgrading, and audit who holds the impersonation role.
docker pull quay.io/keycloak/keycloak:26.7.4PostgreSQL: Security Release Across All Supported Branches
The PostgreSQL security page lists fixes in 18.6, 17.11, 16.15, 15.19 and 14.24. Several issues score CVSS 8.8, including CVE-2026-19385 (pg_dump heap buffer overflow), CVE-2026-18408 (psql \unrestrict), CVE-2026-16239 (type confusion around cursor CLOSE and DECLARE) and CVE-2026-14664 (regexp heap buffer overflow). Check each CVE's affected-versions table, then update the server and client tools together, since pg_dump and psql are affected.
psql -c "SELECT version();"Node.js: Current and LTS Builds
The Node.js release blog shows v26.10.0 (September 22), v24.21.0 (September 9) and v22.23.3 (September 23). Node.js 26 is scheduled to enter LTS in October, after which the project moves to one major release a year. Plan production pinning accordingly.
Action Checklist
- Upgrade Next.js to 16.3.8 or 15.5.27 and review self-hosted ISR/SSG caching.
- Upgrade Keycloak to 26.7.4 and review impersonation permissions.
- Apply the PostgreSQL minor updates to servers and client tooling.
- Plan the Node.js 26 LTS transition.
Not every tool on the watch list published a verifiable release in this window, so only confirmed items are covered.
Comments
Share your thoughts and join the conversation



