05 October, 2026

The Next.js security story changed between 2025 and 2026. It went from a single middleware bypass to a sustained run of advisories, some of them critical.
On May 6, 2026, Next.js patched 13 advisories, including several middleware and proxy bypasses. July 20 added another high-severity bypass affecting App Router apps built with Turbopack and a single locale. The most severe issues came next: August 25 fixed two critical unauthenticated remote code execution flaws, and September 22 fixed another critical RCE in next/og on 16.x. On September 30, a fifth release fixed 7 more vulnerabilities, including a high-severity SSRF in Image Optimization.
Any 15.x app below 15.5.27 or 16.x app below 16.3.8 is missing at least one fix. Next.js 15 leaves security support on October 21, 2026.
This post explains:
Apps on Next.js 13.x or 14.x carry the 2026 vulnerabilities permanently, because neither line receives security fixes anymore. Apps on 15.x or 16.x should be on 15.5.27 or 16.3.8 today, and 16.3.7 does not include the security fixes. Next.js has shipped five security releases since May. May and July fixed middleware and proxy bypasses, August 25 and September 22 fixed critical remote code execution flaws, and September 30 fixed 7 more vulnerabilities, including a high-severity SSRF in Image Optimization. Next.js 15 also leaves security support on October 21, 2026.
Next.js has shipped five security releases since May 2026. The September 30 release left one critical and one high vulnerability unfixed, with no date published.
| Date | Fixed in | Advisories | Headline risk |
|---|---|---|---|
| May 6 | 15.5.18, 16.2.6 | 13 | Middleware bypass, SSRF, XSS, DoS |
| July 20 | 15.5.21, 16.2.11 | 9 | SSRF, Turbopack middleware bypass |
| Aug 25 | 15.5.24, 16.3.3 | 2 | Two unauthenticated RCEs (Windows path traversal, AVIF image handling) |
| Sept 22 | 15.5.26, 16.3.6 | 1 | RCE in next/og (16.x only) |
| Sept 30 | 15.5.27, 16.3.8 | 7 | Image Optimization SSRF, SSG/ISR cache poisoning |
The May release covered middleware and proxy-bypass, denial-of-service, server-side request forgery (SSRF), cache poisoning, and cross-site scripting. One of the 13 was an upstream React Server Components denial-of-service vulnerability, tracked as CVE-2026-23870.
The July release fixed 4 high-severity and 5 medium-severity issues. The high-severity ones were a Server Actions denial of service, a middleware bypass, and two SSRF flaws: one in rewrites() and one in Server Actions on custom servers.
The August 25 release patched two unrelated critical, unauthenticated remote code execution flaws. Next.js moved it forward a day from its planned August 26 date after the second one surfaced. CVE-2026-75604 is a path-traversal flaw affecting self-hosted servers on Windows that use the Pages Router and App Router without Cache Components. GHSA-2xp9-vwfh-vxw4 is an overflow in libheif, reached through the Image Optimization API, and it applies only when image/avif is enabled in next.config.js. Vercel-hosted apps are protected from both. Both are fixed in 15.5.24 and 16.3.3.
The September 22 release was out-of-band. It fixes a remote code execution issue (GHSA-vcvr-r3jv-pc5j) in the Node.js ImageResponse implementation in next/og. It affects versions from 16.2.0 up to, but not including, 16.3.6. Next.js 15.x is not affected, and 15.5.26 adds hardening only. Edge ImageResponse is not affected.
The September 30 release patched 7 vulnerabilities: 1 high, 5 medium, and 1 low. It is smaller than announced. Next.js had planned 9 fixes, including 1 critical and 1 high, and postponed those 2 fixes due to upstream dependency delays. The release post gives no date for them. Version 16.3.7, published September 29, is a bug-fix release and does not contain these fixes. All 7 are fixed in 15.5.27 and 16.3.8.
SSRF in Image Optimization. An attacker-controlled, allow-listed remote URL can reach private IP ranges. Apps with no images.remotePatterns configured are not affected.
Cache poisoning of SSG and ISR pages in self-hosted Pages Router apps, affecting 15.x and 16.x. A page's cache entry can be replaced with content from a different route. Vercel-hosted apps are not affected.
One unauthenticated crafted request can poison the shared cache in apps that combine a root-level catch-all page with SSG or ISR routes.
In App Router apps built with webpack, opengraph-image and twitter-image routes ignore dynamicParams. Turbopack builds are not affected.
With Cache Components enabled, nested 'use cache' functions can serve content from one root param value to another.
A pending use cache fill can leak Draft Mode content to regular visitors when Cache Components or experimental.useCache is enabled.
The next dev Model Context Protocol endpoint lets a malicious website read development data. Production deployments do not serve it.
Next.js also moved to a preannounced security schedule in July, so releases now arrive with advance notice instead of as surprises.
Middleware, called proxy in newer versions, is code that runs before a request reaches a page. Many teams use it as the one place that checks whether a user is logged in.
A middleware bypass is a request that reaches a protected route without the middleware's checks applying. Three 2026 advisories fit that description:
An auth bypass through a segment-prefetch URL (GHSA-267c-6grr-h53f). The first fix was incomplete, and a follow-up advisory, GHSA-26hh-7cqf-hhc6, covered the gap.
A request to the locale-less /_next/data/< buildid >/< page >.json path never triggers middleware. An attacker can read the server-rendered JSON for a protected page without passing the check.
App Router apps built with Turbopack and a single entry in i18n.locales skip their middleware or proxy checks entirely. Affected versions run from 16.0.0 up to 16.2.11.
Vercel stated that it did not deploy new WAF rules for the May release and that these advisories cannot be reliably blocked at the WAF layer. Hosting on Vercel does not substitute for patching.
This is a pattern, not a run of bad luck. A 2025 advisory (GHSA-f82v-jwr5-mffw, Critical) also allowed authorization bypass in apps that checked auth in middleware.
Our recommendation is to treat middleware as a first check, not the only one. Verify the session again in the server code that reads the data: Server Components, Route Handlers, and Server Actions. The cost is a duplicated auth call and slightly more code per route. The gain is that a future bypass exposes a redirect rather than your data. Framework-level hardening, such as the CSP headers and secure cookie configuration covered in Next.js security best practices, reduces exposure even before a patch ships.
No. Next.js 14 reached end of life on October 26, 2025, and is listed as unsupported in the Next.js support policy, along with all older major versions. In Vercel's May advisory, every 13.x and 14.x version is listed as affected, and the fix path is a move to 15.5.18 or 16.2.6.
Next.js 15 is next. The support policy keeps each major in Maintenance LTS for two years after its initial release, and 15 shipped on October 21, 2024. By that rule, 15.x stops receiving security updates on October 21, 2026.
| Version | Status | Security fixes |
|---|---|---|
| 16.x | Active LTS | Yes |
| 15.x | Maintenance LTS | Until Oct 21, 2026 |
| 14.x and older | Unsupported | No |
Find the installed version. Run next --version, then check your lockfile. A ^16.2.0 range in package.json can resolve to an older version than you expect, and the lockfile is what actually deploys.
Compare it to the patched versions. The floor today is 15.5.27 or 16.3.8. Version 16.3.7 is not a security release. Next.js has postponed fixes for 1 critical and 1 high vulnerability, so check the Next.js security advisories for the release that carries them.
Find out whether middleware or proxy guards your routes. If middleware.ts or proxy.ts is your only authorization check, treat the upgrade as urgent.
Check for the specific configurations:
Check for 13.x or 14.x. If you are on either, this is an upgrade decision, not a patch decision.
Moving within a supported line, such as 15.5.x to 15.5.27 or 16.2.x to 16.3.8, is usually a dependency bump plus a test run. It is not guaranteed to be trivial, though: for Maintenance LTS versions, the support policy says updates land as semver-minor releases even when they are breaking changes. Read the release notes before you deploy.
Moving from 13 or 14 to 16 is a migration. Next.js 15 requires React 19 and made params and searchParams asynchronous, so every page and layout that reads them changes. Custom middleware is also affected, since 16 renames it to proxy. Moving in two hops, 14 to 15 and then 15 to 16, lets you isolate what broke at each step. The trade-off is a longer calendar timeline.
You do not have to leave the Pages Router to fix these vulnerabilities. Keep the version upgrade and the App Router migration as separate projects: the upgrade closes the security gap, the migration restructures your app, and combining them makes it hard to tell which change broke what.
A version bump within 15.x or 16.x is work most teams can do alone. The upgrade is a dependency change, the advisories are public, and your existing test suite tells you whether it worked.
Outside help earns its cost on the 13/14-to-16 path when you have custom middleware carrying authorization logic, or a test suite too thin to catch a broken migration. In that case, the auth layer is the part to move carefully.
If your app sits in that second group, or you are not sure which group it falls into, talk to iSyncEvolution about a Next.js upgrade or security review.
No. Next.js 14 reached end of life on October 26, 2025, and receives no security fixes. Upgrade to 15.5.27 or 16.3.8.
It is a class of 2026 advisories in which a crafted request reaches a protected route without middleware or proxy authorization checks applying. Vercel's May release patched several variants, and July added another affecting Turbopack builds with a single locale.
Run next --version in your project, then confirm the resolved version in your lockfile. The lockfile reflects what is actually deployed.
Since July 2026, on a preannounced schedule, roughly monthly, plus out-of-band releases for critical issues such as the one on September 22.
It fixed 7 vulnerabilities: 1 high-severity SSRF in Image Optimization, 5 medium and 1 low. Upgrade to 15.5.27 or 16.3.8. Version 16.3.7 does not include these fixes.
Nikhil Shah is the CTO and Co-Founder of iSyncEvolution, an engineering leader who aligns modern technology best practices with long-term commercial success. A veteran of cloud infrastructure and scalable web/mobile solutions, he specializes in building high-performance software environments. Nikhil helps global brands master their technical roadmaps, optimizing both code performance and development economics to fuel growth.
Written by