Skip to content
Next.js Patches Critical Remote Code Execution Flaw: September 2026 Security Updates Explained
  Posted on 03 Oct, 2026
  Tech News

On September 22, 2026, the Next.js team published an unscheduled security update for a critical flaw that can let an attacker run code on the server of an affected Next.js 16 application. Eight days later, on September 30, 2026, a second release fixed seven more vulnerabilities, and the team said two further fixes are still to come. If your website or web application is built on Next.js, your developers have upgrade work to do this month.

What was announced

Next.js is an open source framework, maintained by Vercel, for building websites and web applications with React. Three announcements on the official Next.js blog make up this story.

Released on September 22, 2026. The Next.js security update post announced versions 16.3.6 and 15.5.26 as an out-of-band release, meaning outside the normal schedule. According to that post, the releases upgrade upstream dependencies, including an image library called Satori, to close an issue that could lead to remote code execution. The post rates the issue as critical. The matching GitHub security advisory GHSA-vcvr-r3jv-pc5j lists a CVSS version 4 score of 9.5.

Released on September 30, 2026. The September 2026 security release post announced versions 16.3.8 and 15.5.27. The advance notice for that release, first published on September 23, 2026, counts the fixes as one high, five medium and one low severity vulnerability.

Announced, with no date given. The same advance notice was updated on September 30, 2026 to say the release covers seven vulnerabilities rather than the nine originally planned. The remaining two, one critical and one high, are described as pending upstream coordination and due in a later Next.js release. No date or technical detail has been published for those two.

Key details

The critical issue sits in a feature most business owners have never heard of. Next.js can generate images on the fly, typically the preview card that appears when a page is shared on social media or in a messaging app. The component that does this is called ImageResponse, in the next/og module. The Next.js post says the flaw affects the Node.js version of ImageResponse and that applications using the Edge version are not affected.

The GitHub advisory adds an important condition: an application is exposed when it passes untrusted input, such as a value taken from the page address, into the SVG content, attributes or styles that ImageResponse renders. A site that builds a share image from a title supplied in the URL is the kind of pattern the advisory describes.

ItemSeptember 22, 2026 updateSeptember 30, 2026 release
StatusReleasedReleased
Patched versions16.3.6 and 15.5.2616.3.8 and 15.5.27
Highest severityCritical (remote code execution)High (server-side request forgery in Image Optimization)
Number of issuesOneSeven: one high, five medium, one low
Versions affected by the top issue16.2.0 up to, but not including, 16.3.6See each advisory linked from the release post
Next.js 15Not affected by the code execution issue; 15.5.26 is described as hardening only15.5.27 is named as the patched release for the 15 line

Several of the September 30 fixes concern caching, according to the release post. In plain terms, the described problems could cause a page to serve the wrong content to visitors, or cause unpublished draft content to appear in public responses when certain newer caching features and Draft Mode previews are used together. One cache issue applies only to self-hosted applications; the post says applications deployed on Vercel are not affected by that one. The high severity item only applies if the application has configured remote image sources, and the low severity item only affects the development server, not production sites.

One easy mistake: version 16.3.7, published on September 29, 2026, is a bug fix release and does not contain the September 30 security fixes, according to the advance notice. Being on 16.3.7 is not the same as being patched.

What this means for your business

This section is our interpretation, not part of the announcements.

  • The risk depends on how your site was built, not just on the version number. A Next.js 16.2 or 16.3 site that generates share images from user-supplied text on a Node.js server fits the conditions in the advisory. A site on Next.js 15, or one that does not use ImageResponse at all, does not fit the critical issue, but may still be covered by the September 30 fixes.
  • Self-hosted applications deserve the closest look. If your application runs on your own servers, containers or a general cloud provider, nobody patches the framework for you. The fix only arrives when your team upgrades and redeploys.
  • Expect one more upgrade soon. With a critical and a high severity fix still outstanding, this is not a single task. Plan for a further release with little notice.
  • Older versions are a separate problem. The Next.js support policy lists 16.x as Active LTS, 15.x as Maintenance LTS, and 14.x and earlier as unsupported. It also says the 15.x line stays in maintenance for two years from its release on October 21, 2024. Check that page for the current status if your site is on 15 or older, because an unsupported version does not routinely receive security fixes.

The location of your business does not change the technical fix. For both US and UK companies, a server compromise that touches personal data can raise notification and contractual questions. That is a matter for your legal adviser, and nothing here is legal advice.

What to do now

  1. Ask your developers or agency which exact Next.js version is running in production. It is recorded in the project's package and lock files.
  2. If you are on 16.x, upgrade to 16.3.8 or later. If you are on 15.x, upgrade to 15.5.27 or later. Both are named in the September 30 release post.
  3. If you cannot upgrade immediately and are on 16.2.0 or later, apply the workaround in the advisory: do not pass user-controlled values into SVG content, attributes or styles rendered by the Node.js ImageResponse.
  4. Have the code searched for uses of next/og and ImageResponse, including opengraph-image and twitter-image routes, and note where the text or styling comes from.
  5. If you are on 14.x or older, start planning a version upgrade rather than waiting for a patch.
  6. Assign someone to watch the Next.js blog for the two outstanding fixes, and agree in advance who approves and deploys an urgent update.

For technical readers

The upstream Satori advisory GHSA-wx4j-mvgx-mqwp describes improper escaping in generated SVG, rated moderate on its own, affecting Satori 0.0.27 up to but not including 0.33.5. The Next.js post explains that the escalation to code execution comes from vulnerabilities in other upstream dependencies in the Node.js rendering path. If you use Satori or a similar image pipeline directly, outside Next.js, review that advisory separately. After upgrading, confirm the resolved version in the lock file and in the deployed build, not just in package.json.

Frequently asked questions

Is my site affected if it runs on Next.js 15?

Not by the critical code execution issue. The September 22 post states that Next.js 15.x is not affected by it and that 15.5.26 contains related hardening only. The September 30 release does name 15.5.27 as a patched version, so 15.x sites should still upgrade.

We host on Vercel. Do we still need to upgrade?

Yes. The posts say that one specific cache poisoning issue does not affect applications deployed on Vercel, but they make no such statement about the critical issue or the other fixes. The stated instruction for all users is to patch the Next.js dependency.

How do I know whether my site uses ImageResponse?

You cannot tell from the outside with certainty. A developer needs to search the code for imports from next/og and for opengraph-image or twitter-image files. If dynamic share images are generated per page, for example for blog posts or product pages, there is a good chance it is in use.

Conclusion

The Next.js releases of September 22 and September 30, 2026 fix one critical and seven further vulnerabilities, and the maintainers have said two more fixes are on the way. For most companies the response is a routine but prompt upgrade to 16.3.8 or 15.5.27, plus a check of how share images are generated; for those on unsupported versions it is the prompt to plan a larger upgrade. Entrant Technologies builds and maintains web applications with React and Node.js; if you want a second opinion on your version or upgrade path, you can contact us.

Post Written by
"Entrant Technologies is one of the leading web, software, iPhone & Android app development company which deliver robust results for great brands worldwide. We deliver software solutions that meet the customers and business expectations."
Latest Blogs
 
If you ask three vendors what it costs to build an AI agent, you will probably get three figures that are far apart, and none of them will be wrong. They are pricing different things: a different scop ...
on 03 Oct, 2026 Read More
 
Most people have been stuck with a bad support bot: it misreads the question, repeats the same help article, and hides the route to a person. The bots people dislike usually fail for design reasons, n ...
on 03 Oct, 2026 Read More
 
Most software projects now include an API, whether or not anyone asked for one by name. Your mobile app needs it to talk to your servers. Your accounting system needs it to receive orders. A partner w ...
on 03 Oct, 2026 Read More