Skip to content
Oday Bakkour
Back to Knowledge Hub

Next.js Security Patch Due Today, Docker Desktop 4.93

Oday Bakkour profile photo
Oday Bakkour
3 min read
Share
Next.js Security Patch Due Today, Docker Desktop 4.93

Executive summary

Next.js: a coordinated security release (16.3.8 and 15.5.27) covering nine vulnerabilities, one critical, is scheduled for today. See the Vercel announcement.

Next.js: v16.3.7 shipped yesterday with a Turbopack fix for a hanging strongly consistent read on a canceled task.

Docker Desktop 4.93.0 (Sept 28) closes a VM-side Unix socket port forward flaw, addresses containerd CVE-2026-53495, and ships Engine v29.8.1. Details in the release notes.

Node.js: v26.10.0 (Current) and v22.23.3 (LTS) landed in the last week.

Next.js: nine fixes due today, upgrade first to 16.3.6

Vercel's pre-announcement lists one critical, two high, five medium and one low severity issue, fixed in 16.3.8 (Active LTS) and 15.5.27 (Maintenance LTS). Details are embargoed until release, so the immediate action is to be on a patched baseline and ready to bump.

The out-of-band September 22 update already fixed a critical upstream issue, and 16.3.6 fixed a remote code execution bug in next/og ImageResponse (GHSA-vcvr-r3jv-pc5j). If you are below 16.3.6 or 15.5.26, stop and upgrade now.

upgrade.sh
# Check what you run
npm ls next

# Move to the current patched line, then to 16.3.8 once published
npm install [email protected]
npm install [email protected]   # after today's release

On the canary channel, v16.4.0-canary.53 enables Cache Components by default in create-next-app, and recent canaries surface security upgrade insights in DevTools and drop the unstable_ prefix from some navigation APIs. Treat canaries as previews, not production targets.

Docker Desktop 4.93.0: isolation and containerd fixes

The 4.93.0 release notes describe a fix for an issue where code inside the VM could request Unix socket port forwards and manipulate arbitrary host paths. Enhanced Container Isolation enforcement was also tightened, and the Linux kernel moved to v7.0.14, restoring MongoDB 8 startup. Bundled components include Docker Engine v29.8.1.

The prior 4.92.0 release updated containerd to v2.3.5 for security, and the 4.93.0 cycle references CVE-2026-53495 in containerd. Verify against the NVD record for affected ranges. Windows admins get a fixed MSI that adds users to the docker-users group, plus a fix for a startup crash (exit code 151) on config files with a UTF-8 BOM.

verify.sh
docker version --format '{{.Server.Version}}'
# expect 29.8.1 after updating Docker Desktop to 4.93.0

Node.js: new Current and LTS builds

The Node.js release blog lists v26.10.0 (Current, Sept 22) and v22.23.3 (LTS, Sept 23), following v24.21.0 (LTS) and v26.8.2 on Sept 9. Pin your runtime in CI and read the changelog for your line before rolling forward.

Dockerfile
# Dockerfile
FROM node:24-alpine   # pin to your LTS line and rebuild to pick up patches

Coverage note

Other tools on the watchlist (Keycloak, Cloudflare, Nuxt, Prisma, Drizzle, PostgreSQL and more) had no verifiable notable release in today's audit sources, so they are omitted rather than padded. Every link above points to an official release page, advisory or CVE record.

Add Oday Bakkour as a preferred source on Google

Comments

Share your thoughts and join the conversation

Leave a Comment

Loading comments...
RELATED