Skip to content
Oday Bakkour
Back to Knowledge Hub

Dev Stack Release Audit: Next.js 16.3.8 SSRF Fix, Keycloak 26.7.4 and PostgreSQL Security Patches

Oday Bakkour profile photo
Oday Bakkour
3 min read
Share
Dev Stack Release Audit: Next.js 16.3.8 SSRF Fix, Keycloak 26.7.4 and PostgreSQL Security Patches

Executive Summary

  • Next.js (high severity): 16.3.8 fixes a server-side request forgery in Image Optimization (GHSA-cjq9-62q9-8jv4) plus five medium and one low advisory. 15.5.27 backports three of the medium fixes.
  • Keycloak: 26.7.4 closes six CVEs, including an impersonation-to-realm-admin escalation (CVE-2026-17526) and an unauthenticated denial of service.
  • PostgreSQL: the latest security release (18.6, 17.11, 16.15, 15.19, 14.24) lists several CVSS 8.8 issues in pg_dump, psql and the core server.
  • Node.js: 26.10.0 (Current), 24.21.0 and 22.23.3 (LTS) are the newest builds, and Node.js 26 is due to enter LTS this month.

Next.js 16.3.8 and 15.5.27: SSRF and Cache Fixes

The v16.3.8 release (September 30) is a security-focused release. Highlights:

The v15.5.27 release backports the metadata-route and both cache-poisoning fixes for the 15.x line. Teams still on 16.3.6 or 15.5.26 (the RCE fix from September 22) should upgrade again.

bash.txt
npm install [email protected] react@latest react-dom@latest
# 15.x line
npm install [email protected]

Until you upgrade, restrict image optimization to known hosts:

next.config.js
// next.config.js
module.exports = {
  images: {
    remotePatterns: [{ protocol: 'https', hostname: 'cdn.example.com' }],
  },
}

Keycloak 26.7.4: Six CVEs Fixed

The Keycloak 26.7.4 announcement (September 16) lists:

  • CVE-2026-17526: the impersonation role can escalate to realm administrator.
  • CVE-2026-79651: unauthenticated denial of service via unbounded locale caching.
  • CVE-2026-19607: username takeover that locks out the victim.
  • CVE-2026-74909: a percent-encoded semicolon bypasses matrix parameter stripping.
  • CVE-2026-90997: default MySQL/MariaDB row counts let stateless replay gates accept reused artifacts.
  • CVE-2026-18212: the SAML redirect DEFLATE helper leaks native zlib state.

The release also moves to Quarkus 3.33.3.2 and fixes a performance regression from 26.6.2. Review the migration guide before upgrading, and audit who holds the impersonation role.

bash.txt
docker pull quay.io/keycloak/keycloak:26.7.4

PostgreSQL: Security Release Across All Supported Branches

The PostgreSQL security page lists fixes in 18.6, 17.11, 16.15, 15.19 and 14.24. Several issues score CVSS 8.8, including CVE-2026-19385 (pg_dump heap buffer overflow), CVE-2026-18408 (psql \unrestrict), CVE-2026-16239 (type confusion around cursor CLOSE and DECLARE) and CVE-2026-14664 (regexp heap buffer overflow). Check each CVE's affected-versions table, then update the server and client tools together, since pg_dump and psql are affected.

bash.txt
psql -c "SELECT version();"

Node.js: Current and LTS Builds

The Node.js release blog shows v26.10.0 (September 22), v24.21.0 (September 9) and v22.23.3 (September 23). Node.js 26 is scheduled to enter LTS in October, after which the project moves to one major release a year. Plan production pinning accordingly.

Action Checklist

  1. Upgrade Next.js to 16.3.8 or 15.5.27 and review self-hosted ISR/SSG caching.
  2. Upgrade Keycloak to 26.7.4 and review impersonation permissions.
  3. Apply the PostgreSQL minor updates to servers and client tooling.
  4. Plan the Node.js 26 LTS transition.

Not every tool on the watch list published a verifiable release in this window, so only confirmed items are covered.

Add Oday Bakkour as a preferred source on Google

Comments

Share your thoughts and join the conversation

Leave a Comment

Loading comments...
RELATED
Next.js 16.3.8 SSRF Fix, Keycloak & Postgres Patches | Oday Bakkour