Next.js RCE, 6 Keycloak CVEs & a Kubernetes Bypass: The Sept 25, 2026 Dev Stack Patch Roundup

Today’s sweep across the stack turned up an unusually dense cluster of security releases — a critical remote code execution fix in Next.js, six CVEs patched in Keycloak, a cross-namespace authorization bypass in Kubernetes, and a run of smaller advisories across Fastify, NestJS, Podman, Auth0, Redis and RabbitMQ. Alongside the security work, React, Astro, Prisma, Laravel and Motion all shipped notable feature releases. Here is what changed, what is breaking, and what to patch first.
Executive Summary
- Next.js 16.3.6 / 15.5.26 (Sept 22) — critical RCE patched in the
next/ogImageResponse pipeline via an upstream Satori dependency. Upgrade immediately if you use Node.js-based ImageResponse. - Keycloak 26.7.4 (Sept 16) — 6 CVEs fixed, including an unauthenticated DoS, a SAML zlib state leak, and an impersonation-role privilege escalation to realm admin.
- Kubernetes CVE-2026-2270 (fixed Sept 23) — confused-deputy bug in kube-controller-manager lets a namespace-scoped user trick the StatefulSet controller into creating pods in namespaces they don’t own.
- Fastify 5.12.5 (Sept 16) closes another security gap after CVE-2026-84504 (CVSS 8.1, request-body replacement via Ajv async validators) earlier this month.
- NestJS 11.2.6 and Hono 4.13.7 both shipped fixes for file-upload/XSS issues (multer CVE-2026-88932 and unescaped JSX string rendering, respectively).
- Podman 6.1.1, Auth0’s AD/LDAP connector, Redis Software, and RabbitMQ (CVE-2026-57219) all received security patches this cycle — details below.
- Feature watch: React 19.3 ships
<ViewTransition>; Astro 7.3.5 adds experimentalrenderComponent(); Prisma ORM 8.0.0-rc.12 lands multi-file schema splitting; Better Auth 1.7.6 and Motion 13.4.4 both shipped within the last 24 hours.
Containers, Edge & Infrastructure
Docker
Docker Engine 29.8.1 and Compose v5.5.1 released Sept 3 fix watch syncing into symlinked directories, exclude Dockerfile/compose files from the initial sync, and now capture lifecycle-hook output in error logs. No breaking changes. See the Compose releases.
Cloudflare
R2 Data Access Logs went GA on Sept 4, recording read/write/list/multipart/delete operations across the S3 API, dashboard, Workers bindings and public buckets, surfaced via Workers Observability (changelog). Separately, Workflows created on or after Sept 10 on the Workers Paid plan now retain completed/errored instance state for only 7 days by default, down from 30 — check your retention assumptions (Workflows changelog).
Vercel / Next.js — Critical RCE
Vercel shipped an out-of-band security release on Sept 22: Next.js 16.3.6 (Active LTS) and 15.5.26 (Maintenance LTS). The fix addresses GHSA-vcvr-r3jv-pc5j, a critical-severity remote code execution issue in the Node.js next/og ImageResponse implementation, caused by improper SVG escaping in the upstream Satori dependency (GHSA-wx4j-mvgx-mqwp). It affects Next.js >=16.2.0 <16.3.6. Edge-runtime ImageResponse usage is not affected. Full details in the official advisory. A further scheduled security release (16.3.7 / 15.5.27, covering 9 more CVEs) is planned for Sept 30.
npm install [email protected] # Active LTS line
npm install [email protected] # Maintenance LTS (hardening only)Kubernetes — Cross-Namespace Authorization Bypass
A confused-deputy vulnerability in kube-controller-manager’s StatefulSet controller, tracked as CVE-2026-2270 and fixed Sept 23, allowed a user with namespace-scoped write access to StatefulSet and ControllerRevision objects to make the cluster-wide controller create a pod in a namespace outside their permissions. The fix restricts ControllerRevision restoration to the spec field. No confirmed exploitation has been reported. Read the security advisory and check your RBAC bindings on StatefulSet/ControllerRevision resources.
Podman
Podman 6.1.1 (Sept 2) fixes CVE-2026-17106 (GHSA-hfg8-hc9c-6c3h), where a crafted tar archive could write outside the extraction directory via malicious links, rooted in the moby/go-archive library. It also fixes a rootlessport dual-stack binding regression under WSL.
Railway & Render
Railway Sandboxes reached general availability on Sept 18. Render now lets you define Workflow services directly in Blueprints (Sept 16) and switched Workflow task runs to a new default "flex" compute plan (Sept 1) — worth a look if you’re on a paid Workflows plan. See the Render changelog.
Identity & Authentication
Keycloak — 6 CVEs Patched
Keycloak 26.7.4 (Sept 16) bundles fixes for six vulnerabilities, alongside a Quarkus bump to 3.33.3.2:
- CVE-2026-90997 — stateless replay-gate bypass via default MySQL/MariaDB row counts
- CVE-2026-79651 — unauthenticated denial of service via unbounded locale caching
- CVE-2026-74909 — percent-encoded semicolon bypasses matrix-parameter stripping in PathMatcher
- CVE-2026-19607 — username takeover leading to account lockout
- CVE-2026-18212 — SAML redirect DEFLATE helpers leak native zlib state
- CVE-2026-17526 — the "impersonation" role can escalate to impersonate a realm administrator
Full write-up in the official release notes. Review the migration guide before upgrading.
Auth0
Multiple advisories landed for the Auth0 AD/LDAP Connector (disclosed Sept 8): CVE-2026-85983 (local privilege escalation via improper startup config handling, CVSS 7.8), plus CVE-2026-85982 (stored XSS) and CVE-2026-85981 (unauthenticated localhost admin panel). All affect connector versions prior to 7.00 — upgrade to 7.00+. See Okta Trust security advisories.
Better Auth & Authentik
Better Auth 1.7.6 shipped Sept 24 with a bannedUserMessage function for custom ban-reason errors, Vercel BotID as a captcha provider, and fixes for over-length password hashing and stale auth-query race conditions. See the changelog. Authentik 2026.8.3 (Sept 17) is a routine patch on the current stable line (release). Auth.js/NextAuth had no new release this week — the project remains in maintenance mode.
Meta-Frameworks & Core Web Standards
React 19.3
React 19.3.0 (Sept 9) adds the <ViewTransition> component for built-in page/element transition animations, plus Fragment Refs support and performance improvements. Non-breaking. See the release notes.
Vue.js & Nuxt
Vue 3.5.43 (Sept 17) is a routine bug-fix release, but 3.6.0-rc.9 (Sept 18) is worth watching as Vue moves toward the 3.6 major with Vapor Mode and compiler changes — a likely breaking upgrade down the line (releases). Nuxt has no update in the last week; the latest is v4.5.2 (Aug 5).
SvelteKit & Svelte
SvelteKit 3.0.0-next.28 (Sept 24) is a pre-release on the SvelteKit 3 track and introduces a breaking change: query parameters beginning with x-sveltekit- are now rejected. SvelteKit 3 is not yet stable (releases). Svelte 5.57.1 (Sept 18) is a non-breaking patch fixing deferred event-listener cleanup.
Astro 7.3.5
Astro 7.3.5 (Sept 24) introduces an experimental renderComponent() function for rendering Astro components with inlined styles/scripts. The same-day @astrojs/[email protected] is a breaking major release: it migrates to @vitejs/plugin-react v6, removes the Babel integration option, and adds optional React Compiler support. See the releases.
Backend Frameworks & Runtimes
NestJS & Node.js
NestJS 11.2.6 (Sept 23) is a security fix: it updates the multer dependency to v2.4.0, closing CVE-2026-88932 (GHSA-3pph-fpjx-jg34) in the file-upload middleware, and fixes error handling so bad field-name uploads now return 400 instead of 500. Node.js 26.10.0 (Current, Sept 22) adds new crypto-parsing and filesystem capabilities; LTS lines 22.23.3 "Jod" and 24.21.0 "Krypton" also shipped this month.
Fastify — Third Security Fix This Month
Fastify 5.12.5 (Sept 16) is a security release (GHSA-4mh8-r7rc-xpvc) following two other high-severity fixes earlier in the 5.12.x line: CVE-2026-84504 (CVSS 8.1, request-body replacement via Ajv async validators, fixed in 5.12.2) and CVE-2026-18504 (schema validation/type-coercion bypass, fixed in 5.12.1). If you’re still on an earlier 5.12.x build, upgrade now.
Hono, ElysiaJS & Express
Hono 4.13.9 (Sept 24) fixes JSX Suspense/ErrorBoundary and JWT validation bugs; the earlier 4.13.7 (Sept 4) was a security release closing an XSS hole where plain strings passed to JSX Suspense/ErrorBoundary/Context.Provider rendered unescaped (releases). ElysiaJS 1.4.30 (Aug 26) is now security-only maintenance while development moves to the in-progress Elysia 2 rewrite. Express has had no release since v5.2.1 (Dec 2025) — no update this cycle.
FastAPI, Django & Laravel
Django 6.0.8 / 5.2.17 (Aug 4) is a security release addressing a denial-of-service issue in GEOS geometry handling (announcement) — the most recent Django release as of today. Laravel Framework 13.33.0 (Sept 22) adds Eloquent vector casts, MariaDB vector distance queries, and queue:pause --all (releases). FastAPI’s latest is 0.141.1 (July 29), a minor fix restoring background-task header propagation.
UI Systems, Styling & Motion
Motion — Daily Patches, New AnimateView
Motion (formerly Framer Motion) is the most active library this week: v13.4.4 and v13.4.3 both shipped Sept 24, fixing children "sticking" during AnimatePresence re-entry and animations not replaying after Suspense reveals memoized content. The broader v13.4.0 (Sept 14) introduced AnimateView, a new component built on React 19.3’s native ViewTransition API. See the changelog.
shadcn/ui
shadcn/ui’s September update moves the cn helper (clsx + twMerge) into a standalone npm package instead of a local lib/utils.ts copy, with a CLI migration command provided. Explicitly non-breaking — your existing lib/utils.ts keeps working. See the changelog.
Radix UI, Tailwind CSS & MUI
No releases in the last 7 days for any of the three. Radix UI’s latest (1.1.23, July 24) added per-primitive subpath entry points for better tree-shaking. Tailwind CSS v4.3.3 (July 16) added --watch --poll CLI support. MUI v9.4.0 (Aug 27) introduced theme.focusVisible for consistent keyboard focus rings. All three releases are non-breaking.
Databases, Caching & Vector Search
PostgreSQL, ClickHouse & DuckDB
PostgreSQL 19 Beta 4 landed Sept 24 ahead of a GA expected around October (announcement); pgvector has no update since its Jan–Mar 2026 release. ClickHouse 26.8 LTS (Sept 1) adds custom HTTP handlers, a pipe operator (|>), and system.user_query_log — note it carries roughly 57 accumulated breaking changes across the 26.3→26.8 LTS line (newsletter). DuckDB’s v2.0-alpha (Sept 2) marks the feature freeze ahead of the "Cyanoptera" major release, expected around October (announcement).
Redis & MongoDB
Redis Software’s Kubernetes operator shipped maintenance releases this month fixing a high-severity credential-wipe bug in Active-Active databases, present since 2023 (release notes). MongoDB’s mongosh shell got a bug-fix release Sept 15; no new MongoDB Server version this week.
Prisma ORM — Breaking Changes Ahead of 8.0 GA
Prisma ORM 8.0.0-rc.12 (Sept 24) adds Postgres full-text search, prepared ORM reads/aggregates, and multi-file schema splitting, with GA expected in October. It carries breaking changes: definePrismaConfig replaces defineConfig, unmapped model names are now taken literally, and dbgenerated is removed. See the release. Drizzle ORM had no dated release surfaced this week.
Supabase & Firebase
Supabase’s September changelog adds AND-filter combinations and more operators to Postgres Changes realtime subscriptions, but also removed the Management API logs.all endpoint on Sept 23 — a breaking change requiring migration to the new ClickHouse-backed logs endpoint (changelog). Firebase’s Admin Python SDK v7.6.0 adds App Check replay protection, and Remote Config moved to usage-based pricing on Sept 1.
Messaging & Task Queues
RabbitMQ 4.3.6 (Sept 16) is a maintenance release; ongoing CVE-2026-57219 covers unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint in certain OAuth2 configurations (advisory). BullMQ’s v6 line introduced a pluggable IQueueBackend abstraction (Redis plus a new Postgres backend) — a breaking change that removes direct access to Queue#client and the legacy repeatable-jobs API. Apache Kafka’s latest is 4.3.1 (June 25), fixing a Kafka Streams RocksDB memory leak; Temporal has shipped nothing new in the last week.
What To Patch First
If you only have time for a handful of upgrades today: patch Next.js if you use Node.js ImageResponse, patch Keycloak to 26.7.4, review your Kubernetes RBAC on StatefulSet/ControllerRevision resources, and confirm you’re past Fastify 5.12.2 and NestJS 11.2.6. Everything else here is feature work worth planning around rather than an emergency.
Comments
Share your thoughts and join the conversation
