Publisha
  • Authors
  • AI Writer
  • About
Publisha

Empowering authors and readers through intelligent tools and stories worth your time. Discover a new perspective every day.

Join the club

Subscribe to get the latest articles and updates directly to your inbox.

Explore

HomeAbout UsOur AuthorsArticlesSeriesAI Writing ToolContact

Write

Start writingAI writing toolYour dashboardHow it works

Legal

Privacy PolicyTerms of ServiceCookie PolicyAccessibility

© 2026 Publisha. All rights reserved.

Designed & developed by Gurman Singh
Publisha
Home/Articles/Software Development

Next.js Security Updates This Month: Which Version You Need

A critical ImageResponse flaw was fixed in Next.js 16.3.6 on 22 Sep, and a nine-vulnerability release is planned for 30 Sep. Here is what to upgrade to and how to check.

Ananya RaoAnanya RaoAuthor3 October 2026·3 min read· 1 views
Reviews
Next.js Security Updates This Month: Which Version You Need
In this article▾
  1. The 22 September fix: a critical issue in ImageResponse
  2. Am I actually exposed?
  3. The 30 September release: nine more vulnerabilities
  4. A quick upgrade checklist
  5. Make the next one less stressful

If you run a Next.js app, September has been an unusually busy month for security. There was a critical out-of-band fix on 22 September, and a second, larger release announced for 30 September. Version numbers are moving quickly, and one of them, 16.3.7, does not contain the security fixes people assume it does. Here is which version you need, what was actually fixed, and how to check your own app.

The 22 September fix: a critical issue in ImageResponse

On 22 September the Next.js team published an out-of-band security update in versions 16.3.6 (Active LTS) and 15.5.26 (Maintenance LTS). The details from the announcement:

  • What: a critical remote code execution issue (advisory GHSA-vcvr-r3jv-pc5j) in the Node.js implementation of ImageResponse in next/og. Under specific conditions, improper escaping in SVG output generated by Satori, an upstream dependency, could lead to remote code execution because of vulnerabilities in other upstream packages.

  • Who is affected: Next.js versions >=16.2.0 <16.3.6. Apps using the Edge implementation of ImageResponse are not affected.

  • Next.js 15.x: not affected by the remote code execution issue, although 15.5.26 includes related hardening.

The fix is to upgrade:

npm install next@16.3.6   # for the 16.3 line
npm install next@15.5.26  # for the 15.5 line (hardening only)

Then redeploy. An upgraded package.json protects nobody until the new build is live.

Am I actually exposed?

Netlify's note on the issue gives a useful way to think about it: a site is affected only if it uses ImageResponse and the image it generates includes untrusted input, such as text or an image loaded from the request. Dynamic social preview images that put a URL parameter or user-submitted title into the picture are the typical case. Sites that only use static images are unlikely to be exposed, but do not rely on that. Upgrade anyway.

To find out whether your code uses the feature at all:

grep -rn "ImageResponse" app src pages 2>/dev/null
npm ls next

The second command shows the exact version installed, including copies pulled in by other packages.

If you cannot upgrade immediately, Netlify's interim advice is to avoid putting untrusted content in ImageResponse elements, or to escape XML before rendering, and to delete vulnerable deploy previews and branch deploys manually instead of waiting for them to expire. Treat that as a stopgap, not a fix.

The 30 September release: nine more vulnerabilities

On 23 September the team gave advance notice of a scheduled security release for 30 September. It will address nine vulnerabilities: one critical, two high, five medium and one low. The patched versions are planned as 16.3.8 and 15.5.27, published together with full advisories covering impact and affected versions.

The same post carries an important update. On 29 September, version 16.3.7 was published with a bug fix, and it does not include the security fixes. If you upgraded to 16.3.7 thinking you were covered, you are only as protected as 16.3.6, which fixes the ImageResponse issue but not the September 30 batch.

Check the Next.js blog and the project's GitHub releases page to confirm that 16.3.8 and 15.5.27 are out, and move to them (or later) as soon as they are.

A quick upgrade checklist

  1. Run npm ls next and note your version and release line.

  2. Upgrade to the patched version for that line, and commit the updated lockfile.

  3. Run your tests and build locally, especially pages that generate images or use middleware.

  4. Redeploy production, then delete old preview and branch deployments.

  5. Confirm the deployed version, not just the version in your repository.

Make the next one less stressful

  • Stay on a supported line. The announcements name 16.3 as Active LTS and 15.5 as Maintenance LTS. Older lines may not receive fixes.

  • Watch the advisories. Follow the Next.js blog or turn on GitHub security alerts for your repository.

  • Automate pull requests. Dependabot or a similar tool can open an upgrade for you the day a patch is out.

  • Keep upgrades small. A project that is one patch behind can upgrade in minutes. A project that is a year behind cannot.

Filed underSoftware DevelopmentWeb DevelopmentGuides & Tutorials
Ananya Rao

Written by

Ananya RaoView profile

On this page

  1. The 22 September fix: a critical issue in ImageResponse
  2. Am I actually exposed?
  3. The 30 September release: nine more vulnerabilities
  4. A quick upgrade checklist
  5. Make the next one less stressful

Keep reading

More stories worth your time

All stories

Have a story of your own?

Publisha is free to start. Write with AI that keeps your voice, and publish in a click.