Next.js RCE Patch, Postgres 28 CVEs: Sept 26 Roundup

Today's audit covers a critical remote-code-execution patch in Next.js, PostgreSQL's largest-ever single security release, an unauthenticated account-takeover fix in Keycloak, and dozens of smaller but consequential updates across containers, identity, meta-frameworks, backend runtimes, databases, UI systems, and job queues. Everything below is sourced from official release notes, security advisories, and changelogs published as of September 26, 2026.
Executive Summary
- Next.js 16.3.6 / 15.5.26 close a critical RCE in the Node.js ImageResponse (next/og) path, caused by an upstream Satori escaping bug. Edge ImageResponse is unaffected; upgrade immediately if you use next/og on Node.js.
- PostgreSQL 18.6, 17.11, 16.15, 15.19, 14.24 shipped 28 CVEs on August 13, 2026 — the most in a single release in the project's history — with 17 rated CVSS 8.0+. PostgreSQL 19 Beta 4 landed September 24.
- Keycloak 26.7.2 patched eight CVEs including CVE-2026-18963, a critical unauthenticated account-takeover flaw, and CVE-2026-15571, a predictable account-linking hash.
- Kubernetes 1.37 graduates emptyDir permission modes and bind mount options for storage security, and moves native histogram metrics support to Beta-on-by-default.
- Docker Desktop 4.91.0 bundles Engine v29.8.0, Compose v5.1.4, and an updated Kind provider image that fixes CVE-2026-46595 and CVE-2026-39834.
- Redis continues patching a string of post-authentication RCE CVEs disclosed since May 2026, with a further hardening release on July 23.
- Cloudflare Workers raised the deploy size ceiling to a flat 64 MiB uncompressed on all plans and added granular per-Worker access roles for teammates, agents, and CI/CD.
- Better Auth 1.7.3 ships an OAuth device-authorization flow and SCIM group support as it absorbs Auth.js/NextAuth, which now receives security-only patches.
- Bun 1.4.2, BullMQ v6 (pluggable Redis/Postgres queue backends), and Nuxt 4.5.1 / 3.21.10 all shipped security or stability patches worth an immediate dependency bump.
Critical: Next.js Remote Code Execution via Satori (next/og)
The headline item today is GHSA-vcvr-r3jv-pc5j, a critical-severity remote code execution vulnerability affecting Next.js versions ≥16.2.0 <16.3.6. The root cause traces to Satori, the SVG-to-image library that powers the Node.js implementation of ImageResponse in next/og. Under specific conditions, improper escaping in Satori's generated SVG output allowed RCE via other upstream dependencies.
The Edge runtime implementation of ImageResponse is not affected — only the Node.js path is impacted. Next.js 15.x does not carry the RCE itself but received the same dependency bump as hardening. Patch now:
npm install [email protected] # Active LTS — patches the RCE
npm install [email protected] # Maintenance LTS — hardening onlyThis lands right before a separately scheduled security release on September 30, 2026 (Next.js 16.3.7 / 15.5.27) covering nine additional vulnerabilities — one critical, two high, five medium, one low — per Next.js's release blog. Teams should plan for a second patch cycle within the week.
Databases, Caching & Vector Search
PostgreSQL: a record CVE batch, plus PG19 Beta 4
On August 13, 2026, the PostgreSQL project shipped 18.6, 17.11, 16.15, 15.19, and 14.24, fixing 28 CVEs — the most ever in one PostgreSQL release — and over 110 bugs. Seventeen carry a CVSS score of 8.0 or higher, and nine explicitly allow arbitrary code execution. Notable individual issues:
- CVE-2026-14672 — a user-enumeration oracle in SCRAM authentication
- CVE-2026-14666 — row-level security decisions served from stale plan caches after a role change
- CVE-2026-14681 — GSSAPI encryption enforcement bypassed when combined with SSL
Development continues in parallel: PostgreSQL 19 Beta 4 was released September 24, 2026. Given the severity of the August batch, prioritize this patch ahead of routine maintenance windows if you're still on an affected minor version.
Redis: a rough year for post-auth RCEs
Redis disclosed five post-authentication RCE vulnerabilities in May 2026 — CVE-2026-23479 (use-after-free in the unblock client flow), CVE-2026-25243 (invalid memory access in RESTORE), CVE-2026-25588/CVE-2026-25589 (RESTORE combined with RedisTimeSeries/RedisBloom modules), and CVE-2026-23631 (Lua use-after-free) — then followed with a further security release on July 23 covering 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5 and 8.8.1 for a Streams shared-NACK use-after-free plus RedisBloom/TDigest out-of-bounds writes. If you run self-managed Redis with modules enabled, confirm you're on a patched minor.
ClickHouse 26.8 and the MongoDB connector
ClickHouse 26.8 adds custom HTTP handlers with dynamic query filtering (useful for exposing ClickHouse as a streaming HTTP API), a new pipe operator (|>) for chaining query transformations, a per-user system.user_query_log table, a URL database engine, and Japanese/Chinese tokenizer support for the text index. Separately, ClickHouse's MongoDB connector moved to Public Beta across all Cloud service tiers, and ClickPipes CDC connectors (Postgres, MySQL, MongoDB) are now GA in the Terraform provider.
Identity & Authentication (IAM)
Keycloak 26.7.2, released August 19, patched eight CVEs: CVE-2026-45292, CVE-2026-14613, CVE-2026-59888, CVE-2026-59889, CVE-2026-15945, CVE-2026-17048, CVE-2026-15571, and CVE-2026-18963. The last is a critical unauthenticated account-takeover flaw; CVE-2026-15571 stems from a predictable account-linking hash that also enables takeover. Both warrant an out-of-cycle upgrade rather than waiting for a routine patch window.
Better Auth 1.7, released August 17 and now at 1.7.3 (September 6), adds a new oauthDeviceAuthorization() flow for OAuth device-code grants, SCIM group and role-projection support, MCP authorization primitives, and unified-identity improvements. This comes as Auth.js formally becomes part of Better Auth — Auth.js/NextAuth now receives security-only fixes while new feature work moves to Better Auth.
Auth0 shipped an Early Access Member Management feature on September 17 letting B2B SaaS organization admins send bulk invitations (up to 10 at a time), pre-assign roles, and route invitees to a specific identity provider via the My Organization API and embeddable UI components. The same release (v202638) lets you assign a custom user_id at signup via api.user.setUserId() inside a pre-user-registration Action. Clerk shipped smaller fixes this month, including an Android SDK bump to 1.1.5 and a fix for ticket-based sign-in/sign-up flows that started before Clerk finished loading.
Containers, Edge & Infrastructure
Docker: Desktop 4.91.0 and Engine v29.8.0
Docker Desktop 4.91.0 (September 14) bundles Engine v29.8.0, containerd v2.3.4, Docker Compose v5.1.4, Docker Build v0.35.0, Docker Agent v1.62.0, and Docker Scout CLI v1.21.0. The Kind cloud-provider image was updated to v0.7.0, closing CVE-2026-46595 and CVE-2026-39834. Notable fixes include the MSI installer ignoring ENGINE=docker-vmm (which silently left Windows Hypervisor Platform disabled) and inaccurate '57 years ago' timestamps in the Volumes/container filesystem browser.
Kubernetes 1.37: storage security and native histograms
Kubernetes v1.37 (August 26) ships emptyDir permission modes and bind mount options as new storage-security primitives, and graduates native histogram support for cluster metrics to Beta, enabled by default. Combined with the Docker/Kind CVE fixes above, this is a good week to bump both your cluster control plane and local dev tooling together.
Cloudflare Workers: bigger deploys, tighter access control
- Sept 4 — compressed size limits removed; Workers now get a flat 64 MiB uncompressed budget on free and paid plans alike.
- Sept 10 — new Workflows on the Paid plan retain completed/errored instance state for 7 days by default, down from 30.
- Sept 15 — per-Worker access roles (Metadata Read-Only, Content Read-Only, Editor, Admin) for teammates, agents, and CI/CD.
- Sept 25 — Workers Metrics charts now render every release in a selected time range, including full gradual-deployment progressions.
On the Vercel side: AWS PrivateLink is now GA, letting deployments reach AWS-hosted databases over a private network path without public exposure, and the AI Gateway added Claude Fable 5.1 access plus user-scoped spend budgets alongside team/project/API-key limits.
Backend Frameworks & Runtimes
Bun 1.4.2 fixes seven issues including two regressions introduced in 1.4.1 — a bun build --compile rename bug affecting Elysia apps and an AsyncLocalStorage memory leak — plus worker_threads 'online' event ordering, GC/JIT crashes, CMYK JPEG decoding in Bun.Image, and a lockfile panic during bun install.
Django published security advisories through August 2026 covering a server-side file-write/request-forgery issue tied to spatial lookups and a denial-of-service risk in check_for_language(); Django 6.1 followed a final 6.0.8 security patch. Laravel 13.26.1 (August 18) formalizes CSRF handling into a new PreventRequestForgery middleware with origin-aware verification. FastAPI's release cadence accelerated through 0.141.1 (July 29), shipping five minor versions in two months.
Database Tools, ORMs & BaaS
Prisma ORM 7.10.0 landed August 26, while the CLI and @prisma/orm-postgres/@prisma/orm-mongo packages moved to Prisma 8 release candidates (8.0.0-rc.15 / rc.11) as of mid-September — general availability is expected within four to eight weeks. Drizzle ORM continued its v1.0.0-beta series, with beta.22 fixing Windows drizzle-kit generate issues and MSSQL column-precision bugs.
Supabase retired the Management API's logs.all endpoint on September 23 in favor of a ClickHouse-backed logs endpoint that accepts ClickHouse SQL only — migrate any log-scraping scripts before the cutover completes. Also shipped: Advisor Health checks surfacing service error rates in Studio, richer Postgres Changes filtering (AND combinators, like/ilike/is operators, column selection), Edge Function limits raised (Pro 500→1,000, Team 1,000→2,000), and org/project-scoped personal access tokens.
UI Systems, Styling & Meta-Frameworks
shadcn/ui moved components to import cn from a standalone cn package this month, cutting the dependency count from two to one with no local helper to maintain — a small but welcome cleanup if you've customized the cn() utility.
Nuxt 4.5.1 and 3.21.10 fix several security issues, alongside a critical fix in @nuxt/devtools 3.3.1 — upgrade the devtools package promptly since it runs with elevated local access during development. Nuxt 4.5 itself (the larger recent release) brought Vite 8, Rspack 2 via Rsbuild, experimental SSR streaming, and a stable error-code system.
On the Svelte side, Svelte 5.57 adds SvelteMap.getOrInsert()/getOrInsertComputed() and a third has function from createContext to check context presence without triggering the usual get-error. SvelteKit 3 is nearing its Release Candidate with new $app/manifest and $app/service-worker modules and shallow routing built into goto.
Background Jobs, Messaging & Task Queues
BullMQ v6 introduces a pluggable IQueueBackend abstraction with both Redis and PostgreSQL backends — a significant architectural shift if you've wanted to run queues without a Redis dependency. Note that v6 removes legacy repeatable jobs and their APIs, so audit your job scheduling code before upgrading from v5.
Temporal shipped Projects for organizing Temporal Cloud namespaces and Nexus endpoints (August 7), plus Serverless Workers for Google Cloud Run and AWS Lambda with automatic autoscaling. Temporal Server 1.31.2 closed CVE-2026-5724, a gRPC streaming-interceptor gap that let the replication API skip authorization entirely under certain cluster configurations — patch self-hosted clusters promptly. Apache Kafka 4.3.1 (June 25) is a bugfix release most notable for fixing a Kafka Streams RocksDB native memory leak.
What to Patch Today
- Upgrade Next.js to 16.3.6 or 15.5.26 immediately if you use next/og's Node.js ImageResponse; watch for the September 30 follow-up release.
- Apply the PostgreSQL 18.6/17.11/16.15/15.19/14.24 security release if you haven't already — this is the largest CVE batch in the project's history.
- Patch Keycloak to 26.7.2 or later to close the unauthenticated account-takeover flaw (CVE-2026-18963).
- Update Docker Desktop to 4.91.0+ and your Kind provider image to v0.7.0 to close CVE-2026-46595 and CVE-2026-39834.
- Confirm Redis is on a patched minor (6.2.23 / 7.2.15 / 7.4.10 / 8.2.8 / 8.4.5 / 8.6.5 / 8.8.1) if you run RedisBloom, RedisTimeSeries, or Streams with modules enabled.
- Bump self-hosted Temporal Server to 1.31.2+ to close the replication-authorization bypass.
- Upgrade @nuxt/devtools to 3.3.1 given its elevated local development privileges.
That's the full sweep for September 26, 2026. Given the concentration of critical-severity items this cycle — Next.js's RCE, Postgres's record CVE batch, and Keycloak's account-takeover fix — prioritize the security patches above ahead of routine feature upgrades.
Comments
Share your thoughts and join the conversation
