Skip to content
Oday Bakkour
Back to Knowledge Hub

SvelteKit 3 Ships, Next.js 16.3.8 Patches 7 Advisories

Oday Bakkour profile photo
Oday Bakkour
4 min read
Share
SvelteKit 3 Ships, Next.js 16.3.8 Patches 7 Advisories

Executive Summary

  • SvelteKit 3.0.0 (Oct 1): major release. Config moves into vite.config.ts, $app/stores and $service-worker are removed, and TypeScript 6, Node 22.17+ and Vite 8 are required. See the announcement.
  • Next.js 16.3.8 / 15.5.27 (Sep 30, security): seven advisories, including a high-severity image optimization SSRF (CVE-2026-94483). Details in the official release post.
  • Node.js 22.23.3 LTS: patches an HTTP/2 use-after-free and updates OpenSSL to 3.5.8, per the release list.
  • Motion 14.0.0 (Oct 2): new major on npm, following Motion 13.5.0's smaller <m> bundle and negative-bounce springs. Release notes were not yet published when we checked.
  • Hono 4.13.13 and Better Auth 1.7.7 were covered in yesterday's audit; nothing new to add there.

SvelteKit 3.0: Vite-Native Config and a Cleaner API Surface

SvelteKit 3.0.0 shipped on October 1 alongside the sv 1.0 CLI. The headline change is that project configuration now lives in vite.config.ts instead of svelte.config.js, and the $lib alias is replaced by the standard subpath import #lib.

Breaking changes to audit before upgrading:

  • Minimum versions: TypeScript 6, Node 22.17, Vite 8.0.12, Svelte 5.56.4 and @sveltejs/vite-plugin-svelte v7.
  • Removed: $app/stores, the $service-worker module, the preloadStrategy option and @sveltejs/kit/node/polyfills. base, assets and resolveRoute are gone from $app/paths.
  • Types moved: remote function types to $app/server, env types to @sveltejs/kit/env, hook types to @sveltejs/kit/hooks, navigation types to $app/navigation and form types to $app/forms.
  • Behavior: goto now rejects unresolvable URLs, clicking a link to the current URL reloads all load functions, and cross-page form actions navigate like native forms.

New additions include the $app/manifest module, a kit.paths.origin option, production sourcemaps and the QUERY HTTP method in +server.js. The team provides an automated migration that rewrites what it can and leaves a TODO list for the rest:

migrate.sh
npx sv migrate sveltekit-3 --tasks all --confirm
# then verify the toolchain
node --version   # >= 22.17
npm ls vite svelte @sveltejs/vite-plugin-svelte

Replace store usage with the rune-based equivalents from $app/state. Note that remote functions are still behind experimental flags, per the announcement.

Next.js 16.3.8 and 15.5.27: Seven Security Fixes

Vercel's September 2026 security release is the one to act on if you self-host. The fixes are in 16.3.8 (Active LTS) and 15.5.27 (Maintenance LTS):

  • High: SSRF during Image Optimization when images.remotePatterns allows an attacker-influenced remote URL (CVE-2026-94483, GHSA-cjq9-62q9-8jv4). Apps without remotePatterns are not affected.
  • Medium: SSG/ISR cache poisoning on self-hosted Pages Router apps (CVE-2026-94543) and with root-level catch-all pages (CVE-2026-94484).
  • Medium: metadata image routes ignoring dynamicParams on webpack builds (CVE-2026-94485); Turbopack builds are not affected.
  • Medium: use cache issues with Cache Components: a root-param cache leak (GHSA-h694-7cp9-m8p3) and Draft Mode content leaking into regular responses (CVE-2026-94544).
  • Low: the next dev Model Context Protocol endpoint did not check request origin (CVE-2026-94486). Production is not affected.
upgrade.sh
npm install [email protected]   # 16.x line
npm install [email protected]  # 15.x line

The announcement notes that a critical and a high-severity fix were postponed earlier because of upstream dependency delays; check the advisory page for the current status of your version.

Node.js 22.23.3 LTS

Node.js 22.23.3 'Jod' (September 23) patches an HTTP/2 use-after-free, bumps OpenSSL to 3.5.8, Undici to 6.28.1 and npm to 10.9.9, and refreshes root certificates to NSS 3.125. It also adds SharedArrayBuffer support to Node-API. Node 24.21.0 (September 8) and Node 26.10.0 (September 22) are the other recent lines; 26.10.0 adds crypto.parsePKCS12() and util.markPromiseAsHandled. In containers, rebuild images so the base layer picks up the patch:

Dockerfile
FROM node:22.23.3-slim
# or: docker pull node:22-slim && docker build --no-cache .

Motion 14.0.0

Motion 14.0.0 was published to npm on October 2, pinning framer-motion 14.0.0 and keeping React 18 and 19 as peer dependencies. The Motion changelog had not listed 14.0.0 when we checked, so review the notes before upgrading. The preceding 13.5.0 added negative bounce values for overdamped springs, shrank the <m> component by 20% and useSpring by 10%, and moved scroll/useScroll offset animations to the main thread.

spring.ts
import { spring } from 'motion'

// 13.5.0+: negative bounce (0 to -1) gives an overdamped spring
const type = spring({ stiffness: 300, bounce: -0.4 })

Registry Snapshot

Latest versions on the npm registry this morning: Next.js 16.3.8, React 19.3.0, Astro 7.3.5, Svelte 5.57.1, SvelteKit 3.0.0, Nuxt 4.5.2, Vue 3.5.43, NestJS 12.1.2, Fastify 5.12.5, Hono 4.13.13, Clerk (@clerk/nextjs) 7.9.10, BullMQ 6.3.11, Drizzle ORM 0.45.3, Prisma 8.0.0-rc.19 (pre-release) and Tailwind CSS 4.3.3. We could not verify changelogs for Docker, Kubernetes, Cloudflare, Keycloak, Authentik, Django, FastAPI, Laravel, PostgreSQL, Redis, MongoDB, ClickHouse or Temporal today, so they are not covered.

Action Checklist

  • Self-hosting Next.js? Move to 16.3.8 or 15.5.27 and review images.remotePatterns.
  • Rebuild Node 22 images on 22.23.3 to pick up the HTTP/2 fix.
  • Plan SvelteKit 3 on a branch: run npx sv migrate sveltekit-3, then fix store and type imports.
  • Read the Motion 14 notes before bumping from 13.x.
Add Oday Bakkour as a preferred source on Google

Comments

Share your thoughts and join the conversation

Leave a Comment

Loading comments...
RELATED