Critical Next.js RCE Fixed as Dev Stack Ships Updates

Executive Summary
- Critical: Next.js shipped an out-of-band security release (v16.3.6 / v15.5.26) on Sept 22 for CVE-2026-94545 (CVSS 9.5), a remote code execution flaw in next/og's ImageResponse renderer on the Node.js runtime. Upgrade immediately if you use next/og.
- Redis shipped a security wave (8.10.2 / 8.8.3 / 8.6.7 / 8.2.10) on Sept 17–18 fixing an ACL-bypass-in-transactions bug and cluster-bus authentication weaknesses.
- RabbitMQ published a fresh advisory batch on Sept 18 (GHSA-j6hc-926v-qwq2, GHSA-5jgm-jxp7-gwjh and others) covering STOMP/MQTT issues, on top of an August critical TLS/JWKS MITM CVE (CVSS 9.2).
- Nuxt v4.5.2 is a security release fixing server-island RCE and route-rule authorization bypass — and Nuxt 3 reached end-of-life on July 31, 2026, so unpatched Nuxt 3 apps get no further fixes.
- PostgreSQL's Aug 13 security release fixed 28 CVEs including several CVSS 8.8+ heap-overflow bugs; Podman 6.1.2 and Django 6.0.8/5.2.17 also carry recent CVE fixes.
- Feature highlights: Cloudflare Workers lifted compressed-size limits to a 64 MiB uncompressed cap; Motion (Framer Motion) shipped v13.4.2 with native React 19.3 View Transitions; NestJS v12 completed its CJS→ESM migration; Prisma v8.0.0-rc.10 moves toward October GA.
Containers, Edge & Infrastructure
Docker
Docker Engine 29.8.1 (Sept 15) fixed dangling images on containerd storage and Windows hard-link preservation. The preceding 29.8.0 minor added a --umask flag and blocked AF_VSOCK socket exploitation. Compose v5.5.1 bumped compose-go to v2.15.0, and Docker Desktop 4.91.0 bundled a Kind image update fixing CVE-2026-46595 and CVE-2026-39834.
Cloudflare
Workers removed compressed-size limits (Sept 4), now capping uncompressed bundles at 64 MiB on every plan, and added per-Worker access roles for teammates, agents and CI (Sept 15). R2 Data Access Logs reached GA covering S3 API, dashboard and Workers-binding access.
Vercel / Next.js
The standout item of the week: Next.js 16.3.6 (Active LTS) and 15.5.26 (Maintenance LTS) patch CVE-2026-94545, a critical (CVSS 9.5) RCE in the Satori-based next/og ImageResponse renderer, caused by improper SVG escaping. It affects Next.js 16.2.0–16.3.5 on the Node.js runtime (Edge is unaffected); 15.x was patched out of caution.
npm install [email protected]
# Maintenance LTS line:
# npm install [email protected]Kubernetes & Podman
Kubernetes' current stable line is v1.34 (latest patch v1.34.11, Aug 11); v1.34 reaches end-of-life Oct 27, 2026, so start upgrade planning now. Podman 6.1.2 fixes CVE-2025-11395, a crafted-tarball/symlink flaw in podman load and podman volume import that could overwrite host files.
Cloud Platforms
Railway (Sept 11) added one-click Postgres major-version upgrades and domain email forwarding. Render (Sept 16) now supports Workflow services via Blueprint YAML. AWS had no standout dated platform release this week.
Identity & Authentication (IAM)
Keycloak's 26.7.0 (Jul 9) remains latest-minor, adding a preview SCIM provisioning API. Better Auth 1.7.5 (Sept 14) added database.schemaName support for direct Postgres connections and fixed cross-schema migration detection. Auth0 shipped a fix upgrading auth0-js to v10.0.0 to resolve CVE-2026-42280, an HS256 token-validation flaw. Notably, Auth.js is now maintained by the Better Auth team, following a July batch of advisory fixes across @auth/core and next-auth v4/v5.
Meta-Frameworks & Core Web Standards
React & Vue
React 19.3.0 (Sept 9) added the <Activity> component; recent 19.2.x patches hardened Server Actions against DoS. React is now governed by the independent React Foundation. Vue 3.5.40 remains latest-tagged, with September activity limited to compiler-sfc, hydration and reactivity bug fixes.
Nuxt
Nuxt 4.5.2 (Aug 5) is a security release: it fixes server-side RCE via server island props, a route-rule authorization bypass, server-component DoS, and cross-user payload disclosure on cached pages. Nuxt 3 reached end-of-life July 31, 2026 — migrate to v4 if you haven't.
SvelteKit & Svelte
SvelteKit now requires Bun 1.4 and fixed ISR data endpoints for server-only routes; a SvelteKit 3 preview shipped 13 releases in July with new $app/manifest and $app/service-worker modules. Svelte 5.57 added new SvelteMap methods and a sv CLI ai-tools add-on.
Astro
Astro 7.3.1 (Sept 3) fixed a CSP violation when combining security.csp with experimental.clientPrerender, and fixed middleware HMR not reacting to imported-module changes.
Backend Frameworks & Runtimes
NestJS & Node.js
NestJS v12.0.4 (Sept 21) continues the v12 major, which migrated all packages from CJS to ESM while relying on Node's require(esm) support to avoid breaking changes; @nestjs/cli is now native ESM and a new nest update command helps migrate v11→v12. Node.js 26.8.2 (Sept 9, Current) is a maintenance/documentation release.
Fastify & Express
Fastify 5.8.5 carries a fix for CVE-2026-25224 (GHSA-mrq3-vjjr-p77c). Express 4.22.2 bundles a body-parser upgrade to ^2.3.0 fixing CVE-2026-12590, where an invalid limit option silently disabled request body size enforcement.
ElysiaJS & Hono
ElysiaJS 1.4.29 normalized multipart/form-data handling for performance; the project's focus has shifted to Elysia 2, with 1.4.x now receiving only security patches. Hono 4.13.x rewrote its RegExpRouter for ~20% faster route matching, added first-class support for the HTTP QUERY method (RFC 10008), and gave its JWT/JWK middleware a realm option.
Python & PHP Stacks
Django's 6.0.8 / 5.2.17 security release (Aug 4) fixed a spatial-lookup flaw letting str/dict values reach GDALRaster, enabling arbitrary file writes reachable by view-only staff users. FastAPI continues its rolling ~v0.141.x cadence with dependency-caching and OpenAPI security-scheme fixes. Laravel 13.32 (Sept 16) added a Mercure broadcast driver and Storage::copyToDisk()/moveToDisk(); Laravel 13's first-party AI SDK (unified text generation, tool-calling agents, embeddings) requires PHP 8.3+.
UI Systems, Styling & Motion
Motion (Framer Motion) v13.4.2 (Sept 23) is the freshest release in this audit, following v13.4.0's AnimateView — View Transitions built on React 19.3's native ViewTransition — and a v13.3.0 perf pass (80% faster spring retargeting). Material UI v9.4.0 (Aug 27) added an opt-in consistent keyboard focus ring via theme.focusVisible. Tailwind CSS remains at v4.3.3 (Jul 16) with no newer release this week. shadcn/ui's September changelog consolidated the cn() helper into a standalone package used across all components; Radix UI's unified package sits at v1.6.7 (Jul 24).
Databases, Caching & Vector Search
PostgreSQL's Aug 13 release (18.6/17.11/16.15/15.19/14.24) fixed 28 CVEs, including CVSS 8.8 heap-overflow bugs in regexp, to_char, plperl and pg_dump — PostgreSQL 14 reaches end-of-life Nov 12, 2026. pgvector v0.8.6 (Jul 29) is the latest stable build.
Redis's 8.10.2 / 8.8.3 / 8.6.7 / 8.2.10 security wave (Sept 17–18) fixed an ACL-bypass-in-transactions bug where MULTI/EXEC-queued commands could still touch keys after ACL permissions were revoked, plus cluster-bus authentication weaknesses. MongoDB 8.2 (Jul 22) added configurable WiredTiger cache sizing and expanded Queryable Encryption. ClickHouse v26.9.2.8 (~Sept 22) makes the query analyzer mandatory and switches max_insert_threads to auto by default. DuckDB v1.5.5 (Jul 22) backported out-of-bounds-read fixes and a deadlock fix in TemporaryMemoryManager.
Database Tools, ORMs & BaaS
Prisma v8.0.0-rc.10 (Sept 12) continues the RC cycle toward October GA, dropping the NEXT_ env-var infix and adding named model/result types. Drizzle ORM's v1.0 line remains in beta (beta.22), with Node.js 22.x now the documented minimum. Supabase removed the Management API's logs.all endpoint on Sept 23 in favor of a ClickHouse-backed logs endpoint, and added combined-filter support to Postgres Changes subscriptions. Firebase's Admin Python SDK v7.6.0 adds App Check replay protection ahead of Firebase ML's June 2027 shutdown.
Background Jobs, Messaging & Task Queues
BullMQ v6.3.6 (Sept 14) added nested duplicate() support on the Bun adapter. RabbitMQ's Sept 18 advisory batch fixed OAuth JWT expiration enforcement for STOMP consumers and unbounded MQTT retained messages, following an August batch that included a High-severity Web STOMP memory-exhaustion bug and a critical TLS/JWKS MITM CVE (CVSS 9.2, fixed in 3.13.15/17, 4.0.20/22, 4.1.11/13, 4.2.6). Apache Kafka 4.3.1 (Jun 25) remains latest, fixing a Kafka Streams RocksDB memory leak. Temporal Server v1.32.0 (Sept 11) is current, alongside a v1.30.7 patch (Sept 18) on the older line.
Bottom Line
If you touch only one thing today, patch next/og: CVE-2026-94545 is a CVSS 9.5 remote code execution bug in a widely used image-generation API, fixed two days ago in Next.js 16.3.6 and 15.5.26. Follow up with the Redis and RabbitMQ security waves, then work through the Nuxt, PostgreSQL, Podman and Django patches on your own upgrade calendar.
Comments
Share your thoughts and join the conversation
