Next.js Patched Seven Security Flaws, but the Critical One Is Still Missing
The latest Next.js security fixes address seven vulnerabilities, including a high-severity server-side request forgery flaw and several ways that cached content can cross boundaries. Yet the critical issue that the project had warned about is not among them.
The project originally planned to address nine vulnerabilities on 30 September. On release day, it cut that number to seven and said one critical and one high-severity issue were still awaiting upstream coordination. Those two issues will be addressed in a later release. Next.js has not published their identities or mechanisms.
That leaves defenders with two jobs. They need to deploy the fixes that exist now, while recognising that this release does not close the entire risk announced a week earlier.
The fixed versions are clear, but the advisory ranges are not
The operational release vehicles are Next.js 16.3.8 and 15.5.27. Version 16.3.8 lists all seven advisories. Version 15.5.27 lists three.
The underlying advisory records are less precise. Several patched-version fields still contain literal placeholders such as 16.3.? and 15.5.?. One advisory creates a more serious conflict: the 15.5.27 release page lists the metadata-image issue, but its own advisory says only versions from 16.0.0 are affected and gives only a 16.3-series patched placeholder.
BlackTree is therefore treating the release pages as proof of the packages shipped, while preserving the advisory conflict instead of inventing a clean 15.x range. Operators should not assume that all seven vulnerabilities affect both branches.
| Issue | What makes it reachable | 16.3.8 | 15.5.27 |
|---|---|---|---|
CVE-2026-94483, GHSA-cjq9-62q9-8jv4 |
An attacker can control or influence a host already allowed by images.remotePatterns, letting Image Optimisation reach unintended destinations such as private IPs. |
Listed | Not listed |
CVE-2026-94485, GHSA-f87g-xv8r-7p7x |
An App Router webpack build uses metadata image routes and deliberately excludes dynamic segments. | Listed | Listed, but the advisory currently describes only 16.x |
CVE-2026-94543, GHSA-4jqv-mc3x-m676 |
A self-hosted Pages Router application uses SSG or ISR. Vercel says its own deployments are unaffected. | Listed | Listed |
CVE-2026-94484, GHSA-mcj8-r9mp-w47p |
A root-level catch-all page operates with statically generated or ISR routes. | Listed | Listed |
CVE-2026-94544, GHSA-3w37-wq28-93x7 |
Cache Components or experimental.useCache handles overlapping Draft Mode and ordinary requests for the same key. The advisory names only 16.3.0 as affected. |
Listed | Not listed |
GHSA-h694-7cp9-m8p3, no CVE currently exposed |
Nested use cache functions read a root parameter while Cache Components are enabled. The advisory names only 16.3.0 as affected. |
Listed | Not listed |
CVE-2026-94486, GHSA-39w2-rjm5-chcv |
A developer runs next dev and visits a malicious website able to reach its MCP endpoint. Production is unaffected. |
Listed | Not listed |
One request can cross a trust boundary
The high-severity issue is not a universal Next.js SSRF. It depends on images.remotePatterns containing a hostname whose DNS or destination an attacker can influence. In that configuration, an allow-listed image URL can make the server-side optimiser request private addresses or other unintended targets.
The cache flaws are narrower, but potentially persistent. They can substitute one route’s content for another, serve content generated for the wrong root parameter, or leak Draft Mode material into an ordinary response. If affected output is prerendered or passed into a downstream cache, the wrong content can outlive the request that created it.
That does not justify purging every cache before investigating. Teams should first map the affected routes and features, upgrade and redeploy, then invalidate entries that could have been created through the vulnerable path.
The low-severity MCP issue belongs to development environments, not production. A malicious site visited by a developer can read information exposed by next dev, including project paths, route inventory, logs and source snippets from errors. Development machines still hold valuable code and credentials, so a production-only patch inventory would miss this exposure.
What Next.js operators should do now
BlackTree operational analysis: use the published fixes and your application configuration to prioritise the following checks. These recommendations are not evidence of compromise.
- Upgrade Next.js 16 deployments to 16.3.8. Use 15.5.27 for supported 15.x deployments covered by that release, while keeping the metadata-image branch conflict documented.
- Rebuild and redeploy from a clean dependency installation. Verify the version in the running artefact, not only in
package.jsonor a lockfile. - Audit
images.remotePatterns, App Router metadata images, root catch-all routes, SSG and ISR, Cache Components, Draft Mode and nesteduse cachefunctions. - Invalidate only application, proxy or CDN entries that may contain output from an affected cache path, then confirm that revalidation behaves as expected.
- Update development environments and prevent untrusted networks or browser content from reaching
next dev. - Track the later release for the deferred critical and high-severity issues. Do not assign them CVEs, attack paths or affected versions before the project publishes those details.
Hosting architecture matters. Netlify recommends upgrading Next.js and using its OpenNext adapter version 5.16.1. Its default auto-installed adapter updates on redeployment; pinned installations need a manual upgrade. Old public deploy previews and branch deploys may still need attention. This is Netlify-specific guidance, not a requirement for every Next.js deployment.
Next.js 16.3.7 is not the security release. The project explicitly said it contained a bug fix only. Teams that upgraded early need to move again.
The official announcement and advisories do not report exploitation in the wild. That is an evidence limit, not proof that exploitation is absent. The available fixes should be deployed according to actual feature exposure.
This September release is separate from the two unauthenticated RCE paths fixed in Next.js during August. The versions, vulnerabilities and deployment conditions are different.
Sources
- Next.js, Upcoming Next.js September Security Release, published 23 September 2026. Inline revisions dated 29 and 30 September provide no publication times.
- Next.js 16.3.8 release, published 30 September 2026.
- Next.js 15.5.27 release, published 30 September 2026.
- The seven issue-specific Next.js advisories linked in the deployment matrix, published 30 September 2026.
- Netlify, Next.js Security Release, September 2026, published 30 September 2026. No publication time is provided.


