Next.js Security Update Released: Critical Vulnerabilities Addressed in Versions 16.3.8 and 15.5.27

Vercel has officially rolled out critical security updates for Next.js, addressing multiple vulnerabilities ranging from high-severity Server-Side Request Forgery (SSRF) to cache poisoning and information disclosure flaws. The patches, which were initially previewed by the development team last week, experienced minor delays due to upstream dependency complications. However, updates are now live and publicly available across supported branches, specifically targeting Active LTS version 16.3.8 and Maintenance LTS version 15.5.27.
The disclosure highlights the inherent complexities of maintaining modern, highly optimized full-stack web frameworks. As JavaScript frameworks evolve to incorporate advanced performance features such as incremental static regeneration, server-side component caching, and experimental build pipelines, the surface area for edge-case security risks expands correspondingly. Developers maintaining self-hosted instances or enterprise-grade applications are strongly urged to update their dependencies immediately to mitigate operational and security risks.
Background and Chronology of the Vulnerability Disclosure
The timeline of this security release spans several weeks of coordinated vulnerability discovery, internal testing, and dependency resolution. Last week, Vercel issued an advance notice warning developers of an imminent security advisory. That initial rollout was temporarily halted due to unforeseen blocks within upstream dependencies—a common friction point in the interconnected JavaScript ecosystem, where core framework maintainers must wait for downstream or side-channel library fixes before finalizing their own patches.
With those dependencies resolved, Vercel published the full advisory stack, issuing CVE identifiers for the affected components. The response underscores the framework’s reliance on proactive reporting channels, notably Vercel’s Open Source Bug Bounty program hosted on Hackerone. Security researchers and independent vulnerability hunters who discovered these flaws channeled their findings through standardized responsible disclosure protocols, allowing the Next.js core engineering team to patch the holes before widespread exploitation could occur in production environments.
Detailed Breakdown of Identified Vulnerabilities and Vector Mechanics
The latest security advisory covers a total of seven distinct CVEs and GitHub Security Advisories (GHSAs), spanning varying degrees of severity. Each vulnerability targets a specific mechanism within the Next.js compilation, rendering, or caching architecture.
Server-Side Request Forgery (SSRF) in Image Optimization
Tracked under CVE-2026-94483 and GHSA-cjq9-62q9-8jv4, this high-severity flaw impacts the Next.js Image Optimization pipeline. Under specific conditions, an attacker-controlled remote URL that has been successfully allow-listed can manipulate requests to trigger Server-Side Request Forgery. This could potentially allow actors to probe private IP ranges or internal network endpoints that should otherwise remain isolated from external web traffic. Vercel noted that applications which do not configure the images.remotePatterns parameter are completely unaffected by this vulnerability.
Cache Poisoning and Content Substitution in SSG and ISR
Three distinct vulnerabilities involve cache poisoning mechanisms across Static Site Generation (SSG) and Incremental Static Regeneration (ISR) architectures. CVE-2026-94543 (GHSA-4jqv-mc3x-m676) affects self-hosted Next.js applications utilizing the Pages Router. In these setups, a page’s cache entry can be forcibly replaced with content from an entirely different route. Consequently, affected pages serve incorrect, mismatched content to subsequent visitors until the cache entry undergoes manual or automated revalidation. Notably, applications deployed natively on Vercel’s managed infrastructure are immune to this specific vector.
A closely related vulnerability, CVE-2026-94484 (GHSA-mcj8-r9mp-w47p), demonstrates how root-level catch-all pages combined with SSG/ISR routes allow unauthenticated, crafted requests to poison shared response caches. This leads to cross-user content substitution and persistent denial-of-service conditions.
App Router Metadata and Dynamic Parameter Bypasses
For developers utilizing the modern App Router, CVE-2026-94485 (GHSA-f87g-xv8r-7p7x) introduces an information disclosure risk specifically tied to webpack-built applications. Metadata image routes—such as opengraph-image and twitter-image—incorrectly ignore the dynamicParams route segment option. Attackers can deliberately query metadata image URLs for dynamic segments that developers intended to exclude via generateStaticParams(). Applications built using Turbopack bypass this vulnerability entirely and remain unaffected.
Caching Anomalies and Draft Mode Leaks
Two specialized caching flaws have also been closed. GHSA-h694-7cp9-m8p3 addresses a cache leak across root parameter values in nested ‘use cache’ functions. When Cache Components are enabled, nested caching functions can generate faulty cache keys that omit enclosing root parameters, resulting in data cross-contamination between different user contexts or routing parameters.
Furthermore, CVE-2026-94484 (also referenced alongside GHSA-3w37-wq28-93×7) highlights a risk where pending use cache fills share states across requests without verifying Draft Mode boundaries. A regular, unauthenticated visitor whose request overlaps with an editor’s Draft Mode session can inadvertently receive unpublished content. If that request triggers a page prerender, the draft content gets permanently baked into the static cache, exposing sensitive draft data to the general public.
Development Server Model Context Protocol Information Disclosure
Finally, a low-severity information disclosure vulnerability (CVE-2026-94486 / GHSA-39w2-rjm5-chcv) affects the Next.js development server (next dev). The built-in Model Context Protocol endpoint lacked origin verification checks. This oversight allowed malicious third-party websites visited by a developer to read sensitive development metrics, including local disk paths, route inventories, local error snippets, and debugging logs. Production environments do not initiate this endpoint, restricting the exposure window exclusively to local development machines.
Analysis of Broader Implications for Enterprise and Self-Hosted Deployments
The nature of these vulnerabilities offers a compelling case study in the security challenges of modern frontend frameworks. As Next.js bridges the gap between traditional static site generators and dynamic server-rendered applications, caching layers have grown exceptionally sophisticated. However, caching introduces complex state-management problems where a single flaw in key generation or validation can cascade into widespread cache poisoning, data leaks, or denial of service.
For enterprise teams, the dichotomy between managed infrastructure and self-hosted environments is starkly highlighted in this advisory. Self-hosted instances—whether running on bare metal, AWS EC2, Google Cloud, or custom Kubernetes clusters—bear the administrative burden of applying immediate patches. In contrast, cloud-managed deployments often absorb platform-level mitigations more transparently, though dependency updates remain mandatory to secure application-layer logic.
Security analysts emphasize that development teams must incorporate automated dependency monitoring into their CI/CD pipelines. Relying on manual updates for framework packages increases the window of exposure, particularly for high-severity vulnerabilities like SSRF that can be chained into deeper internal network reconnaissance.
Official Security Posture and Reporting Protocols
Vercel continues to advocate for transparency and collaboration within the open-source community. Through its active bug bounty program on HackerOne, the company incentivizes security researchers to audit Next.js and its supporting ecosystem. Developers or security professionals with questions regarding vulnerability management, disclosure timelines, or remediation strategies are advised to direct inquiries to Vercel’s dedicated security team via email.
Actionable Next Steps for Developers
To secure applications against these threats, engineering teams should execute the following steps immediately:
- Audit current Next.js package versions across all active repositories.
- Upgrade Active LTS installations to version 16.3.8.
- Upgrade Maintenance LTS installations to version 15.5.27.
- Review image optimization configurations (
images.remotePatterns) and ensure strict boundary parameters are enforced. - Evaluate self-hosted caching mechanisms, particularly if utilizing the Pages Router with SSG/ISR or enabling experimental caching features like
use cache.
Prompt action ensures application integrity, protects user privacy, and prevents potential cache manipulation attacks across production environments.







