Plate 66
Next.js 16.3.8 security release: SSRF, cache, and OG routes (and the earlier next/og RCE)
Next.js 16.3.8 (30 Sep 2026) covers image SSRF and cache bugs. CVE-2026-94545, the next/og RCE, was patched in 16.3.6 and is not a 16.3.8 fix.
Aditya Challa7 min read
Next.js 16.3.8 security release: SSRF, cache, and OG routes (and the earlier next/og RCE)
Next.js 16.3.8 is a security release. The GitHub tag v16.3.8 was published 2026-09-30 16:13 UTC (30 Sep 2026, 21:43 IST). Vercel’s write-up is the September 2026 security release. The same fixes are published on the 15.5 line as 15.5.27.
That release is not the announcement for CVE-2026-94545. The earlier next/og remote-code-execution issue was patched in 16.3.6. This post keeps the two apart. ShopperCove has not reproduced either issue. There is no exploit walkthrough here.
Related posts on ShopperCove:
- Next.js 16 App Router Production Checklist (2026)
- TanStack Start XSS: Patch CVE-2026-102989 Now
- Next.js 16.3 for AI Coding Agents (2026)
- React 19.3 View Transitions & Fragment Refs: Frontend Guide (2026)
- SvelteKit 3 Is Here (Oct 1, 2026): Migration Checklist for Teams
No affiliate links. No paid ads.
Two September fixes, not one
Read this before you file a ticket that says “16.3.8 fixes CVE-2026-94545.” It does not. The 16.3.8 notes do not list that CVE or GHSA-vcvr-r3jv-pc5j.
Earlier: next/og RCE, patched in 16.3.6
GitHub advisory GHSA-vcvr-r3jv-pc5j was published 22 Sep 2026. When this page was checked on 3 Oct 2026, its CVE field was empty. Do not treat a CVE number as something that advisory page printed.
What the advisory does say:
- Package:
nexton npm. - Affected versions:
>=16.2.0 <16.3.6. - Patched version named on the advisory: 16.3.6.
- The Node.js
ImageResponsefromnext/ogcan lead to remote code execution when attacker-controlled values are passed into SVG content, attributes, or styles. - Applications that use the Edge
ImageResponseimplementation are not affected. Applications that do not pass attacker-controlled values into those SVG fields are not affected either. - GitHub displays the advisory as Critical, with a score of 9.5.
- If you cannot upgrade immediately, the advisory’s workaround is to stop passing attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js
ImageResponsefromnext/og.
Vercel’s 22 Sep 2026 security update is the release note for that fix: 16.3.6 (Active LTS) and 15.5.26 (Maintenance LTS). That post says these releases upgrade upstream dependencies, including Satori. It also says Next.js 15.x is not affected by the remote code execution issue; 15.5.26 is described there as related hardening. The commands on that post are npm install next@16.3.6 for the 16.3 line and npm install next@15.5.26 for 15.5 (hardening only).
Tenable’s CVE-2026-94545 page, checked="true" 3 Oct 2026, shows Published: 2026-09-30 and Updated: 2026-09-30 (no clock on those fields). Its description is the upstream Satori issue: starting in version 0.0.27 and prior to 0.33.5, Satori does not properly escape certain values before including them in generated SVG, so crafted values can be interpreted as SVG markup. The page says 0.33.5 contains a patch, and its reference list includes GHSA-vcvr-r3jv-pc5j and the Next.js v16.3.6 tag. Tenable also prints more than one CVSS base (v2 7.5, v3 9.8 labeled Critical, v4 5.3). Those are Tenable’s figures, not the 9.5 shown on the GitHub advisory. Use CVE-2026-94545 as Tenable’s id for this Satori / next/og issue, not as a number copied from the GitHub advisory body.
A release newer than 16.3.6 meets the version line the GitHub advisory calls patched. That is ordinary version ordering. It is not the same sentence as “16.3.8 fixes CVE-2026-94545.” The 16.3.8 post does not list GHSA-vcvr-r3jv-pc5j.
Later: what 16.3.8 actually ships
The v16.3.8 tag (author eps1lon) says the release contains security fixes and then names one High, five Medium, and one Low issue. It does not name CVE-2026-94545.
The September 2026 security release says a fix for one critical vulnerability and one high-severity vulnerability was postponed because of upstream dependency delays, and that updates are now in v16.3.8 and v15.5.27. The Impact section that follows does not label any item Critical, and it does not name GHSA-vcvr-r3jv-pc5j. This article does not guess which postponed bug that “critical” sentence refers to, and it does not attach that sentence to CVE-2026-94545.
Commands printed on the 16.3.8 post:
Issues named on the 16.3.8 post
Severities and ids below are copied from Vercel’s Impact section. Descriptions are shortened from that page, not from a lab repro.
| Severity | Id on the Vercel post | What that post says |
|---|---|---|
| High | CVE-2026-94483 / GHSA-cjq9-62q9-8jv4 | Image Optimization SSRF. An attacker-controlled, allow-listed remote URL can lead to SSRF (for example to private IP ranges). If no images.remotePatterns are configured, the application is not affected. |
| Medium | CVE-2026-94543 / GHSA-4jqv-mc3x-m676 | Self-hosted Pages Router apps that use SSG or ISR can have a page’s cache entry replaced with content from a different route, so the page serves the wrong content until revalidation. Applications deployed on Vercel are not affected. |
| Medium | CVE-2026-94484 / GHSA-mcj8-r9mp-w47p | A root-level catch-all page together with SSG or ISR routes can have the shared response cache poisoned by a single unauthenticated crafted request. Vercel describes cross-user content substitution and persistent denial of service. |
| Medium | CVE-2026-94485 / GHSA-f87g-xv8r-7p7x | On App Router apps built with webpack, metadata image routes such as opengraph-image and twitter-image ignore dynamicParams. Someone can request metadata image URLs for dynamic segments excluded from generateStaticParams(). Turbopack builds are not affected. |
| Medium | GHSA-h694-7cp9-m8p3 (no CVE id printed next to this item) | With Cache Components, a 'use cache' function that calls another 'use cache' function that reads a root param can be keyed incorrectly, so content for one root-param value can be served for another. Vercel says the leaked values cannot be attacker-controlled. |
| Medium | CVE-2026-94544 / GHSA-3w37-wq28-93x7 | A pending 'use cache' fill can leak Draft Mode content into a regular response and, if that request prerenders, into the persisted page until revalidation. Affected if Cache Components (or experimental.useCache) are on and Draft Mode previews return draft-dependent content from cached functions. |
| Low | CVE-2026-94486 / GHSA-39w2-rjm5-chcv | The next dev MCP endpoint does not check which site a request comes from. A malicious site opened by the developer can read development data (project path, source snippets from error reports, route inventory, development logs). Production does not serve this endpoint. |
CVE-2026-94543, CVE-2026-94544, and CVE-2026-94545 are three different ids. Only 94545 is the earlier next/og / Satori item patched in 16.3.6. 94543 and 94544 are cache issues named on the 16.3.8 post.
What to change in the repo
- Read the resolved
nextversion in the lockfile, not only the range inpackage.json. - If the app is on
>=16.2.0and below 16.3.6 and it uses Node.jsImageResponsefromnext/ogwith attacker-controlled SVG input, follow GHSA-vcvr-r3jv-pc5j. The patched version that advisory names is 16.3.6. EdgeImageResponseis out of scope for that advisory. Do not close this item by writing “fixed in 16.3.8” in the changelog for CVE-2026-94545. - For the issues in the table above, install the release Vercel points at: 16.3.8 on the 16.3 line, or 15.5.27 on the 15.5 line.
- After install, check the conditions Vercel uses to limit impact:
images.remotePatterns(image SSRF), self-hosted Pages Router SSG/ISR versus Vercel-hosted, a root catch-all plus SSG/ISR, webpack versus Turbopack for metadata image routes, Cache Components /'use cache'(including nested root params and Draft Mode), and whether anyone is runningnext devagainst untrusted pages in a browser. - Redeploy. A lockfile bump that never ships does not change production.
- If you also run TanStack Start, that stack has its own advisory. See TanStack Start XSS: Patch CVE-2026-102989 Now. Do not merge the two CVEs into one upgrade note.
The Next.js 16 App Router checklist is the production-hygiene companion. Next.js 16.3 for AI coding agents is about agent tooling, not this security tag. React 19.3 and SvelteKit 3 are separate framework releases from the same week; they do not patch these Next.js advisories.
Sources
- GitHub tag v16.3.8 (published 2026-09-30 16:13 UTC)
- September 2026 security release (16.3.8 and 15.5.27)
- GHSA-vcvr-r3jv-pc5j (patched in 16.3.6; CVE field empty on the page checked 3 Oct 2026)
- Next.js security update, 22 Sep 2026 (16.3.6; 15.5.26 hardening; 15.x not affected by the RCE)
- Tenable CVE-2026-94545 (page shows Published 2026-09-30; Satori text plus references to the Next.js advisory and v16.3.6)
No affiliate offer on this post.
Lab evidence
What I found running this
Vendor-attributed from the v16.3.8 tag, the September 2026 security release, GHSA-vcvr-r3jv-pc5j, the 22 Sep 2026 security update, and Tenable CVE-2026-94545, re-fetched 3 Oct 2026. Tenable page showed Published 2026-09-30; GHSA CVE field empty. No PoC. Affiliates: 0.
Related links
Plate 69
Next.js 16 App Router Production Checklist (2026)
A practical Next.js 16 App Router production checklist for Server Components, PPR, caching, streaming, metadata, and SEO.
1 Oct 2026
Plate 34
ast.literal_eval vs json.loads: Localhost Lab
1 Oct 2026
Plate 35
ipaddress vs String Prefix Allowlist: Localhost Lab
Hands-on ipaddress CIDR containment vs naive string prefix allowlists: real checks/s, measured on Linux localhost today in this hands-on lab for SREs.
1 Oct 2026