September 22 Dev Stack Audit: Next.js Ships Emergency Security Patch, Redis Fixes Critical RCE Bug, Auth0 Discloses Four CVEs

Audit window: 2026-09-21 06:00 UTC to 2026-09-22 06:00 UTC. Next.js confirmed an out-of-band critical security release landing today, Redis's 8.10.x line carries forward a critical RDB-loading memory-corruption fix, and Fastify, Auth0, and Podman each disclosed advisories in the same window. Below is what shipped, what's still a draft, and what needs a patch today.
Executive Summary
- Next.js: an out-of-band critical security release fixing an issue in an upstream dependency ships today as 16.3.6 (Active LTS) and 15.5.26 (Maintenance LTS), tracked as GHSA-vcvr-r3jv-pc5j; full advisory details land with the release.
- Redis: the 8.10 line carries forward fixes for CVE-2026-62356, a heap out-of-bounds write from a miscalculated CMSketch RDB-loading buffer, plus a malicious-RDB memory-corruption path Redis says may lead to remote code execution, a TLS client-cert auth bypass via an embedded NUL byte, and a TLS use-after-free. Current patch is 8.10.2.
- Fastify: GHSA-4mh8-r7rc-xpvc (CVSS 5.9) — a single unauthenticated request to a route calling reply.trailer() over HTTP/2 crashes the whole server process. Fixed in 5.12.5.
- Auth0: four new CVEs disclosed against the AD/LDAP Connector (stored XSS, local privilege escalation, an unauthenticated localhost admin panel) and the react-native-auth0 SDK (improper credential-cache isolation). See the Auth0 community security bulletin for CVE IDs and affected versions.
- Podman: v6.1.1 fixes a path-traversal bug (CVE-2026-17106) where a crafted tar archive could write outside the extraction directory during image or container extraction.
- Elsewhere: Kubernetes v1.37 adds volume-mount hardening controls, React 19.3.0 ships ViewTransition and Fragment Refs, and Node.js 26.8.2 bumps undici, OpenSSL, and npm.
Next.js: Out-of-Band Critical Security Release
On September 21, Next.js published a pre-announcement for a critical, out-of-band security release fixing an issue in an upstream dependency, shipping today, September 22, under advisory GHSA-vcvr-r3jv-pc5j. Credited researchers are Josh Story, Karim Rahal, and Sebastian Silbermann. The fix lands on both actively maintained lines: 16.3.6 on the Active LTS (16.x) line and 15.5.26 on the Maintenance LTS (15.x) line. Next.js has not yet published the full technical writeup or CVE record — that follows the release — so treat this as confirmed-critical, details-pending, and plan to re-check the advisory once it's live rather than skip the upgrade while waiting.
npm install [email protected]
# Maintenance LTS line
npm install [email protected]This is the second out-of-band Next.js security release in as many months — last month's AVIF Image Optimization RCE (GHSA-2xp9-vwfh-vxw4) and Windows-hosted-server RCE (GHSA-p293-qw3h-jr36) are still showing up in dependency scans for projects that haven't moved past 16.3.3 / 15.5.24. Bumping today's release covers both.
Redis: Critical RDB-Loading Memory Corruption
The Redis 8.10 line, per the official 8.10 release notes, carries fixes for four distinct issues. The headline is CVE-2026-62356: a heap out-of-bounds write caused by a miscalculated buffer size when loading a CMSketch data structure from an RDB file. A related fix addresses a malicious RDB payload carrying an out-of-range SLOT_INFO slot id, which Redis's own notes describe as capable of causing memory corruption that may lead to remote code execution. Two further fixes close a TLS client-certificate authentication bypass triggered by an embedded NUL byte in the certificate, and a TLS use-after-free.
Any deployment that loads untrusted or third-party RDB snapshots, or that accepts TLS client certificates from outside a fully trusted set of clients, should treat this as a same-day upgrade. The current patch carrying all four fixes forward is 8.10.2.
Fastify: HTTP/2 Trailer Crash
Fastify disclosed GHSA-4mh8-r7rc-xpvc (CVSS 5.9): calling reply.trailer() on a route served over HTTP/2 throws an uncaught exception, because Transfer-Encoding: chunked — which trailers rely on — is forbidden under HTTP/2. A single unauthenticated request to an affected route is enough to crash the entire server process, not just the request. Fixed in 5.12.5.
npm install [email protected]Identity & Authentication
- Auth0 published four new advisories this cycle, three against the AD/LDAP Connector — a stored XSS, a local privilege escalation, and an unauthenticated admin panel reachable on localhost — and one against the auth0/react-native-auth0 SDK, an improper credential-cache isolation bug. Exact CVE IDs and affected version ranges are in the Auth0 community security bulletin. Anyone running the AD/LDAP Connector on-prem should prioritize the admin-panel exposure first — it doesn't require credentials to reach.
- Authentik 2026.8.3 (Sept 17) is a routine bug-fix release: admin file-search case sensitivity, JSON field relation models in search autocomplete, and an employee_department blueprint typo, following 2026.8.1 and .2 earlier in the month.
- Better Auth climbed from 1.7.3 to 1.7.5. 1.7.3 restored the 1.6 account core schema to avoid a disruptive backfill on upgrade, and added Cloudflare as a built-in OAuth social provider with PKCE support.
Containers, Edge & Infrastructure
Podman & Kubernetes
- Podman v6.1.1 fixes CVE-2026-17106 (GHSA-hfg8-hc9c-6c3h): a crafted tar archive with malicious links could extract files outside the target directory during image or container extraction. The same release fixes rootlessport dual-bind (-p 0.0.0.0:... -p [::]:...) and the WSL force_port_listen option for Windows-host port forwarding.
- Kubernetes v1.37 adds two storage-hardening fields: emptyDir.mode, to set exact Unix permission bits instead of the hardcoded 0777, and bindMountOptions on volumeMounts, letting the container runtime apply noexec/nosuid/nodev flags. Both close a long-flagged gap where a compromised process could execute arbitrary binaries from a writable volume. They sit behind the EmptyDirVolumeMode and VolumeBindMountOptions feature gates and are Linux-node only for now.
Cloudflare Workers
Three changes landed on Workers this month: a tripled bundle-size ceiling to 64 MiB uncompressed on every plan (Sept 4), granular per-Worker permissions with four roles for teammates, agents, and CI/CD (Sept 15), and Python 3.14 support for Python Workers on compatibility dates from Sept 8 onward.
Meta-Frameworks
- React 19.3.0: a new <ViewTransition /> component with an addTransitionType API, Fragment Refs (refs on <Fragment>), a browser() API for browser-only code inside Suspense boundaries, independent transition rendering so a slow transition no longer blocks unrelated ones, and Trusted Types API integration.
- Astro 7.3.3 (Sept 16): 25+ patch fixes covering trailing-slash redirect responses, SVG style hashing for CSP, dev-server startup performance, and image-endpoint locale handling. Companion packages — @astrojs/vue 7.0.3, @astrojs/react 6.0.6, @astrojs/cloudflare 14.3.2 — updated the same day.
- Nuxt 4.5.1 and 3.21.10 are patch releases addressing several security issues on the 4.x and 3.x lines respectively; @nuxt/devtools also picked up a critical fix in 3.3.1. Nuxt 4.5 itself, the minor these patch, shipped on Vite 8 with Rspack 2 / Rsbuild support, experimental SSR streaming, and a new stable error-code system.
- Svelte 5.57: SvelteMap gains getOrInsert / getOrInsertComputed, createContext returns a has() check, <select> supports defaultValue, and svelte/server exports new render/CSP types. SvelteKit 3 is now at release-candidate stage.
Backend Frameworks & Runtimes
- Node.js 26.8.2: dependency bumps to undici 8.10.2, OpenSSL 3.5.8, npm 11.19.1, and corepack 0.36.0, plus riscv64 build improvements.
- Hono v4.13.8 (Sept 15) fixes JSX/DOM keyed-update performance, an AWS Lambda streaming bug, and Accept-header handling. Worth a second look if you're not yet current: 4.13.7 (Sept 4) carried an XSS fix for JSX boundary components — Suspense, ErrorBoundary, and Context.Provider — that's easy to miss if you jumped straight to 4.13.8.
- NestJS's @nestjs/core climbed to 12.0.3, a patch on top of the ESM-first, Vitest/oxlint-by-default NestJS 12 line. FastAPI is current at 0.141.1, a routine point release on its usual fast cadence.
Databases & Messaging
- ClickHouse branched 26.9 on Sept 16 (first build 26.9.1.1629). The prior line, 26.8 LTS, added background queries, pipelined SQL, new Japanese/Chinese text tokenizers, expanded data-lake integrations, and a per-user system.user_query_log table.
- RabbitMQ 4.3.6 (Sept 16): maintenance release on the 4.3.x line — quorum-queue compaction, 32 strict priority levels, delayed retries, and the Khepri-only metadata store.
- BullMQ climbed to 6.3.8 (Sept 18), fixing PostgreSQL LISTEN connection retry after a failed connection attempt and deduplication-key cleanup across language bindings — relevant if you've adopted the pluggable Postgres backend BullMQ 6.0 introduced in July.
- Apache Kafka 4.4.0 has not shipped yet — per the Apache release plan, it's still in post-code-freeze stabilization. Worth watching rather than acting on today.
What to Patch Today
- Next.js — upgrade to 16.3.6 / 15.5.26 as soon as it's published today; this is a critical out-of-band release and the advisory is still filling in behind it.
- Redis — move to 8.10.2 if you haven't; CVE-2026-62356 and the SLOT_INFO RDB bug both touch untrusted-input paths that are easy to hit by accident.
- Fastify — 5.12.5 if you serve HTTP/2 and use reply.trailer() anywhere; this is an unauthenticated, single-request denial of service.
- Auth0 AD/LDAP Connector — prioritize the unauthenticated localhost admin panel exposure, then the privilege-escalation and XSS fixes.
- Podman — 6.1.1 if you extract container/image archives from any source you don't fully control.
- Everyone else — Kubernetes 1.37, React 19.3.0, Astro 7.3.3, Nuxt 4.5.1/3.21.10, Svelte 5.57, Node 26.8.2, Hono 4.13.8, RabbitMQ 4.3.6, and BullMQ 6.3.8 carry no urgent CVEs but are worth staying current on.
Version numbers and dates above are current as of this audit's window; confirm against the linked release notes before rolling any of this out to production — the Next.js and Nuxt advisories in particular were still filling in technical detail at publication time.
Comments
Share your thoughts and join the conversation
