Security Update: Multiple vulnerabilities in Next.js

September 30, 2026

The Next.js team has disclosed seven security vulnerabilities in Next.js (one high, five medium, one low), patched on September 30, 2026 in 15.5.27 and 16.3.8. The issues span server-side request forgery (SSRF), cache poisoning, and information disclosure. Several of them do not affect apps hosted on Netlify. Here’s what Netlify customers need to know.

Summary

Some of these vulnerabilities affect Next.js sites hosted on Netlify (details in Impact on Netlify), so if you run Next.js on Netlify, we strongly recommend upgrading next to 15.5.27 or 16.3.8 and redeploying. The OpenNext Netlify Next.js adapter must also be updated to @netlify/plugin-nextjs 5.16.1; it’s auto-installed by default, so a redeploy picks it up (a manual upgrade is only needed if you pin the version). See What should I do? for full steps.

Vulnerabilities

All issues are patched in 15.5.27 and 16.3.8.

VulnerabilitySeverityAffected
GHSA-cjq9-62q9-8jv4 / CVE-2026-94483 — Image optimizer SSRFHigh16.x with an attacker-controlled remote host in images.remotePatterns
GHSA-4jqv-mc3x-m676 / CVE-2026-94543 — Cache poisoning of SSG/ISR pages (cross-route)Medium15.x/16.x Pages Router apps with SSG/ISR and a root catch-all route
GHSA-mcj8-r9mp-w47p / CVE-2026-94484 — Cache poisoning via encoded paths / /index (SSG/ISR)Medium15.x/16.x apps combining a root catch-all with SSG/ISR routes
GHSA-f87g-xv8r-7p7x / CVE-2026-94485 — Metadata image dynamicParams bypass (information disclosure)Medium16.x App Router Webpack builds using metadata image routes
GHSA-h694-7cp9-m8p3 — Cache leak across root param values in nested use cacheMedium16.3.x with Cache Components + nested use cache reading root params
GHSA-3w37-wq28-93x7 / CVE-2026-94544 — Draft Mode use cache content leakMedium16.3.x with Cache Components / useCache, Draft Mode, and draft-dependent cached content
GHSA-39w2-rjm5-chcv / CVE-2026-94486 — Development MCP information disclosureLow16.x development servers (next dev) with the MCP endpoint

Impact on Netlify

Not affected on Netlify

  • GHSA-cjq9-62q9-8jv4 (Image optimizer SSRF): Netlify projects are not affected. Image optimization on Netlify is handled by Netlify Image CDN — a separate service outside your project’s functions — so the vulnerable Next.js image-optimizer code path is not used, and the Image CDN has its own protections against this class of SSRF.
  • GHSA-3w37-wq28-93x7 (Draft Mode use cache content leak): Netlify projects are not affected. This leak requires two requests to share a single server process’s in-flight cache fill. On Netlify’s serverless architecture each request is served by its own isolated invocation, so the required overlap cannot occur.
  • GHSA-39w2-rjm5-chcv (Development MCP information disclosure): Netlify projects are not affected. This affects the next dev development server only; Netlify serves production builds, which do not expose the development MCP endpoint.

Information disclosure

GHSA-f87g-xv8r-7p7x (Metadata image dynamicParams bypass) can expose content from routes excluded via dynamicParams through metadata image routes. It only affects Webpack builds; Turbopack builds are not affected. On Netlify, apps that use a Webpack build are affected; upgrading Next.js resolves it.

Cache poisoning and availability

GHSA-4jqv-mc3x-m676 and GHSA-mcj8-r9mp-w47p affect apps with SSG/ISR routes behind a root catch-all.

  • GHSA-4jqv-mc3x-m676 (cross-route cache poisoning): Pages Router apps with SSG/ISR and a root catch-all route are affected on Netlify. Upgrading Next.js resolves the poisoning on its own. The fix also changes how cache entries are keyed, so you should update the Netlify adapter (5.16.1) as well — otherwise prerendered pages miss the cache and re-render (a serving/performance regression, not a security one). See What should I do?.
  • GHSA-mcj8-r9mp-w47p (encoded paths / /index): App Router apps with a prerendered catch-all route are affected by an availability issue — certain valid percent-encoded URLs can return an error (HTTP 500) instead of the page. Upgrading Next.js resolves it.
  • GHSA-h694-7cp9-m8p3 (cache leak across root param values): affects Next.js 16.x apps using Cache Components with a nested use cache that reads root params (e.g. locale or region segments) — an enclosing cache entry can be keyed without the root param and reused across values, so content produced for one value can be served for another. Upgrading Next.js resolves it.

What should I do?

We strongly recommend upgrading as soon as possible:

  • Upgrade next to 15.5.27 or 16.3.8 and redeploy.

The OpenNext Netlify Next.js adapter that runs your app must also be updated to v5.16.1:

  • Auto-installed adapter (default): redeploy — the update is applied automatically.
  • Manually installed adapter: upgrade @netlify/plugin-nextjs to v5.16.1 and redeploy. We recommend not pinning the adapter version so future fixes ship automatically.

Note that any publicly available deploy previews and branch deploys may remain vulnerable until they are automatically deleted. Consider deleting these deploys manually.

Resources