Next.js 16.4 Ships, 16.3.8 Fixes Seven Security Bugs

Two things matter for Next.js teams today: Next.js 16.4 landed on October 6 and now recommends Cache Components for every app, and the September 30 security release (16.3.8 and 15.5.27) fixed seven vulnerabilities, one of them a high-severity SSRF. This audit covers what could be verified against primary sources in this run.
Executive Summary
- Security: Next.js 16.3.8 and 15.5.27 fix 1 high, 5 medium and 1 low severity issue, led by an SSRF in Image Optimization (CVE-2026-94483).
- Feature: Next.js 16.4 makes Cache Components the default for new create-next-app projects and adds ensureStatic, navigation() and prefetch().
- Tooling: next upgrade --agent and the experimental agentUpgrade and agentFeedback options arrive in 16.4.
- React: React 19.3 ships with 16.4, with stable View Transitions, Fragment Refs and the new browser() API.
- Scope note: No other tool on the audit list had a change confirmed against a primary source in this run, so none are padded in here.
Next.js security release: patch now
The September 2026 security release ships in 16.3.8 (Active LTS) and 15.5.27 (Maintenance LTS). A fix for one critical and one high issue was postponed upstream and is expected in a later release, per the advance notice. Upgrade with:
npm install [email protected] # for 15.5
npm install [email protected] # for 16.3What was fixed, with severity and who is exposed:
- High, SSRF in Image Optimization (CVE-2026-94483, GHSA-cjq9-62q9-8jv4): an allow-listed remote URL can reach private IP ranges. Not affected if no images.remotePatterns is configured.
- Medium, cache poisoning of SSG/ISR pages in self-hosted Pages Router apps (CVE-2026-94543). Vercel deployments are not affected.
- Medium, cross-user content substitution with a root-level catch-all page plus SSG/ISR (CVE-2026-94484).
- Medium, App Router metadata image routes ignore dynamicParams in webpack builds (CVE-2026-94485). Turbopack builds are not affected.
- Medium, cache leak across root params in nested use cache functions (GHSA-h694-7cp9-m8p3).
- Medium, pending use cache fills can leak Draft Mode content into regular responses (CVE-2026-94544).
- Low, the next dev Model Context Protocol endpoint does not verify request origin (CVE-2026-94486). Development only.
Next.js 16.4: Cache Components become the recommendation
The 16.4 release post states that Cache Components will be the default in Next.js 17 and recommends it for every app now. Enable it in an existing project with two flags:
import type { NextConfig } from 'next';
const nextConfig: NextConfig = {
cacheComponents: true,
partialPrefetching: true,
};
export default nextConfig;Guarantee static routes with ensureStatic
ensureStatic fails the build if dynamic content sneaks into a route. It accepts "navigation", "prefetch" or "shell", and works on pages and layouts:
export const ensureStatic = 'navigation';
export default function Page() {
return (
<>
<UserAvatar /> {/* fails the build: dynamic */}
<Content />
</>
);
}Defer work past prefetch with navigation()
Awaiting navigation() keeps a component out of the prefetch so it renders only on a real navigation. A matching prefetch() does the same for the route shell.
import { navigation } from 'next/cache';
async function Thread({ id }) {
await navigation();
const thread = await getThread(id);
// ...
}Agent-assisted upgrades
The new --agent flag prepares migration guides, codemods and verification steps for a coding agent:
npx next@canary upgrade --agent=latestThe experimental reminder policy defaults to security, per the release post:
const nextConfig: NextConfig = {
experimental: {
agentUpgrade: 'security', // or 'latest' | false
},
};Performance and bundle changes
- Turbopack disk cache is 20-25% smaller thanks to Zstandard compression.
- Lazy server HMR only applies updates to routes a request needs.
- Shorter production CSS Module class names and export mangling shrink bundles.
- Experimental options include turbopackGc, turbopackLazyDynamicImports, worker threads and additional roots for pnpm and Bun global stores.
React 19.3 highlights
React 19.3 adds stable ViewTransition, refs on Fragment and a browser() API for browser-only subtrees:
import { use } from 'react';
import { browser } from 'react-dom';
function TimeZone() {
use(browser()); // suspends on server, not on client
const tz = new Intl.DateTimeFormat().resolvedOptions().timeZone;
return <p>{tz}</p>;
}Action items
- Upgrade to [email protected] or [email protected] today, or move to 16.4.
- If you use images.remotePatterns, review allow-listed hosts after patching.
- Review the Node.js security releases page alongside your Next.js patching, since the runtime is part of your attack surface.
- Plan your Cache Components migration ahead of Next.js 17.
Sources: Next.js 16.4, September 2026 security release, React 19.3.
Comments
Share your thoughts and join the conversation



