Next.js 16.3.8 Security Release: 7 Flaws Fixed Today

Executive summary. Scope note: this audit verified Next.js and Node.js against primary sources today. The other stacks on the watch list were not confirmed against a primary source in this run, so they are not covered. The Next.js security release was announced in the Next.js advance notice.
- Next.js published 16.3.8 and 15.5.27 on September 30 with security fixes. Upgrade self-hosted apps first.
- The advance notice says the release addresses seven vulnerabilities: one high, five medium, one low. Two others (one critical, one high) were deferred to a later release pending upstream coordination.
- Version 16.3.7 (September 29) was a bug fix only and does not contain the security patches.
- Node.js 26.10.0 (Current) and 24.21.0 (LTS) are the latest lines per the Node.js releases page; no new Node.js security release today.
Next.js 16.3.8 and 15.5.27: what was fixed
The headline item is a high-severity server-side request forgery in Image Optimization (GHSA-cjq9-62q9-8jv4). Per the advisory, an attacker can abuse allow-listed remote URLs to reach private IP addresses and internal systems. It is listed as CVE-2026-94483, CVSS 8.3. Apps with no configured remote patterns are not affected.
Even after upgrading, audit which hosts you allow. The advisory recommends checking that every host in images.remotePatterns is one whose DNS you control or trust:
import type { NextConfig } from 'next'
const config: NextConfig = {
images: {
remotePatterns: [
// Be specific: exact hostname, https only, scoped path
{ protocol: 'https', hostname: 'cdn.example.com', pathname: '/images/**' },
],
},
}
export default config
The remaining advisories are medium or low severity (links point to the GitHub advisories):
- Metadata image route disclosure via dynamicParams bypass (medium)
- Cache poisoning of SSG and ISR pages in self-hosted apps (medium) and a related cross-user content substitution (medium)
- Draft mode content leak through use cache (medium) and cache leak in nested cache functions (medium)
- Information disclosure in the development server MCP endpoint (low)
The 15.5.27 backport covers the metadata image route and SSG/ISR cache poisoning fixes. Upgrade within your current major line:
# Next.js 16.x
npm install [email protected]
# Next.js 15.x
npm install [email protected]
npx next --versionReminder: the critical and high issues deferred from this release are still open. Watch the Next.js blog and GitHub advisories for the follow-up release.
Node.js: 26.10.0 and 24.21.0 LTS
Per the Node.js GitHub releases, v26.10.0 (September 22) added crypto.parsePKCS12(), openAsBlobSync, util.throttle and util.debounce, and v24.21.0 (LTS, September 8) updated root certificates and dependencies. The most recent security release listed on the Node.js vulnerability blog is dated July 29, 2026.
What to do today
- Upgrade Next.js to 16.3.8 or 15.5.27 and redeploy; prioritize self-hosted and image-optimization-heavy apps.
- Tighten images.remotePatterns to specific hosts and paths.
- If you use use cache or draft mode, purge shared caches after deploying.
Comments
Share your thoughts and join the conversation



