logo
Next JS Development

05 October, 2026

Nextjs Security Vulnerabilities

Executive Summary: Is Your Next.js Application Secure in 2026?

The Next.js security story changed between 2025 and 2026. It went from a single middleware bypass to a sustained run of advisories, some of them critical.

On May 6, 2026, Next.js patched 13 advisories, including several middleware and proxy bypasses. July 20 added another high-severity bypass affecting App Router apps built with Turbopack and a single locale. The most severe issues came next: August 25 fixed two critical unauthenticated remote code execution flaws, and September 22 fixed another critical RCE in next/og on 16.x. On September 30, a fifth release fixed 7 more vulnerabilities, including a high-severity SSRF in Image Optimization.

Any 15.x app below 15.5.27 or 16.x app below 16.3.8 is missing at least one fix. Next.js 15 leaves security support on October 21, 2026.

This post explains:

  • What each of the five shipped 2026 releases fixed, in one timeline table
  • Why middleware or proxy should not be your only authorization check, and what a second check costs
  • Which configurations turn the RCEs into real exposure: Windows self-hosting, image/avif enabled, and Node.js ImageResponse on 16.x
  • How to check your deployed version and configuration in 5 steps
  • What upgrading involves within a supported line versus moving from 13/14 to 16
  • When your team can handle this internally and when outside help earns its cost

Apps on Next.js 13.x or 14.x carry the 2026 vulnerabilities permanently, because neither line receives security fixes anymore. Apps on 15.x or 16.x should be on 15.5.27 or 16.3.8 today, and 16.3.7 does not include the security fixes. Next.js has shipped five security releases since May. May and July fixed middleware and proxy bypasses, August 25 and September 22 fixed critical remote code execution flaws, and September 30 fixed 7 more vulnerabilities, including a high-severity SSRF in Image Optimization. Next.js 15 also leaves security support on October 21, 2026.

What Did Each 2026 Next.js Security Release Fix?

Next.js has shipped five security releases since May 2026. The September 30 release left one critical and one high vulnerability unfixed, with no date published.

DateFixed inAdvisoriesHeadline risk
May 615.5.18, 16.2.613Middleware bypass, SSRF, XSS, DoS
July 2015.5.21, 16.2.119SSRF, Turbopack middleware bypass
Aug 2515.5.24, 16.3.32Two unauthenticated RCEs (Windows path traversal, AVIF image handling)
Sept 2215.5.26, 16.3.61RCE in next/og (16.x only)
Sept 3015.5.27, 16.3.87Image Optimization SSRF, SSG/ISR cache poisoning

May 6, 2026: Middleware, Proxy and SSRF Vulnerabilities

The May release covered middleware and proxy-bypass, denial-of-service, server-side request forgery (SSRF), cache poisoning, and cross-site scripting. One of the 13 was an upstream React Server Components denial-of-service vulnerability, tracked as CVE-2026-23870.

July 20, 2026: Turbopack Middleware Bypass and SSRF Issues

The July release fixed 4 high-severity and 5 medium-severity issues. The high-severity ones were a Server Actions denial of service, a middleware bypass, and two SSRF flaws: one in rewrites() and one in Server Actions on custom servers.

August 25, 2026: Two Critical Remote Code Execution Vulnerabilities

The August 25 release patched two unrelated critical, unauthenticated remote code execution flaws. Next.js moved it forward a day from its planned August 26 date after the second one surfaced. CVE-2026-75604 is a path-traversal flaw affecting self-hosted servers on Windows that use the Pages Router and App Router without Cache Components. GHSA-2xp9-vwfh-vxw4 is an overflow in libheif, reached through the Image Optimization API, and it applies only when image/avif is enabled in next.config.js. Vercel-hosted apps are protected from both. Both are fixed in 15.5.24 and 16.3.3.

September 22, 2026: Critical RCE in next/og

The September 22 release was out-of-band. It fixes a remote code execution issue (GHSA-vcvr-r3jv-pc5j) in the Node.js ImageResponse implementation in next/og. It affects versions from 16.2.0 up to, but not including, 16.3.6. Next.js 15.x is not affected, and 15.5.26 adds hardening only. Edge ImageResponse is not affected.

September 30, 2026: Image Optimization SSRF and SSG/ISR Cache Poisoning

The September 30 release patched 7 vulnerabilities: 1 high, 5 medium, and 1 low. It is smaller than announced. Next.js had planned 9 fixes, including 1 critical and 1 high, and postponed those 2 fixes due to upstream dependency delays. The release post gives no date for them. Version 16.3.7, published September 29, is a bug-fix release and does not contain these fixes. All 7 are fixed in 15.5.27 and 16.3.8.

  • GHSA-cjq9-62q9-8jv4 (CVE-2026-94483, High)

    SSRF in Image Optimization. An attacker-controlled, allow-listed remote URL can reach private IP ranges. Apps with no images.remotePatterns configured are not affected.

  • GHSA-4jqv-mc3x-m676 (CVE-2026-94543, Medium)

    Cache poisoning of SSG and ISR pages in self-hosted Pages Router apps, affecting 15.x and 16.x. A page's cache entry can be replaced with content from a different route. Vercel-hosted apps are not affected.

  • GHSA-mcj8-r9mp-w47p (CVE-2026-94484, Medium)

    One unauthenticated crafted request can poison the shared cache in apps that combine a root-level catch-all page with SSG or ISR routes.

  • GHSA-f87g-xv8r-7p7x (CVE-2026-94485, Medium)

    In App Router apps built with webpack, opengraph-image and twitter-image routes ignore dynamicParams. Turbopack builds are not affected.

  • GHSA-h694-7cp9-m8p3 (Medium)

    With Cache Components enabled, nested 'use cache' functions can serve content from one root param value to another.

  • GHSA-3w37-wq28-93x7 (CVE-2026-94544, Medium)

    A pending use cache fill can leak Draft Mode content to regular visitors when Cache Components or experimental.useCache is enabled.

  • GHSA-39w2-rjm5-chcv (CVE-2026-94486, Low)

    The next dev Model Context Protocol endpoint lets a malicious website read development data. Production deployments do not serve it.

Next.js also moved to a preannounced security schedule in July, so releases now arrive with advance notice instead of as surprises.

What Is the Next.js Middleware and Proxy Bypass Vulnerability?

Middleware, called proxy in newer versions, is code that runs before a request reaches a page. Many teams use it as the one place that checks whether a user is logged in.

A middleware bypass is a request that reaches a protected route without the middleware's checks applying. Three 2026 advisories fit that description:

  • May 2026: App Router Segment-Prefetch Authorization Bypass

    An auth bypass through a segment-prefetch URL (GHSA-267c-6grr-h53f). The first fix was incomplete, and a follow-up advisory, GHSA-26hh-7cqf-hhc6, covered the gap.

  • May 2026: Pages Router and i18n Authorization Bypass

    A request to the locale-less /_next/data/< buildid >/< page >.json path never triggers middleware. An attacker can read the server-rendered JSON for a protected page without passing the check.

  • July 2026: Turbopack and Single-Locale Middleware Bypass

    App Router apps built with Turbopack and a single entry in i18n.locales skip their middleware or proxy checks entirely. Affected versions run from 16.0.0 up to 16.2.11.

Vercel stated that it did not deploy new WAF rules for the May release and that these advisories cannot be reliably blocked at the WAF layer. Hosting on Vercel does not substitute for patching.

This is a pattern, not a run of bad luck. A 2025 advisory (GHSA-f82v-jwr5-mffw, Critical) also allowed authorization bypass in apps that checked auth in middleware.

Our recommendation is to treat middleware as a first check, not the only one. Verify the session again in the server code that reads the data: Server Components, Route Handlers, and Server Actions. The cost is a duplicated auth call and slightly more code per route. The gain is that a future bypass exposes a redirect rather than your data. Framework-level hardening, such as the CSP headers and secure cookie configuration covered in Next.js security best practices, reduces exposure even before a patch ships.

Does Next.js 14 Still Receive Security Fixes?

No. Next.js 14 reached end of life on October 26, 2025, and is listed as unsupported in the Next.js support policy, along with all older major versions. In Vercel's May advisory, every 13.x and 14.x version is listed as affected, and the fix path is a move to 15.5.18 or 16.2.6.

Next.js 15 is next. The support policy keeps each major in Maintenance LTS for two years after its initial release, and 15 shipped on October 21, 2024. By that rule, 15.x stops receiving security updates on October 21, 2026.

VersionStatusSecurity fixes
16.xActive LTSYes
15.xMaintenance LTSUntil Oct 21, 2026
14.x and olderUnsupportedNo

How Do I Check Whether My Next.js App Is Affected?

1. Check the Installed Next.js Version

Find the installed version. Run next --version, then check your lockfile. A ^16.2.0 range in package.json can resolve to an older version than you expect, and the lockfile is what actually deploys.

2. Compare the Version With the Patched Releases

Compare it to the patched versions. The floor today is 15.5.27 or 16.3.8. Version 16.3.7 is not a security release. Next.js has postponed fixes for 1 critical and 1 high vulnerability, so check the Next.js security advisories for the release that carries them.

3. Check Whether Middleware or Proxy Handles Authorization

Find out whether middleware or proxy guards your routes. If middleware.ts or proxy.ts is your only authorization check, treat the upgrade as urgent.

4. Check for Vulnerable Configurations

Check for the specific configurations:

  • Turbopack with a single locale
  • Pages Router with i18n
  • Node.js ImageResponse on 16.x
  • Self-hosting on Windows, or image/avif enabled in next.config.js
  • images.remotePatterns configured
  • A self-hosted Pages Router app with SSG or ISR pages, or a root-level catch-all page combined with SSG or ISR routes
  • Cache Components or experimental.useCache enabled

5. Check Whether You Are Running Next.js 13 or 14

Check for 13.x or 14.x. If you are on either, this is an upgrade decision, not a patch decision.

What Does Upgrading Next.js Actually Involve?

Moving within a supported line, such as 15.5.x to 15.5.27 or 16.2.x to 16.3.8, is usually a dependency bump plus a test run. It is not guaranteed to be trivial, though: for Maintenance LTS versions, the support policy says updates land as semver-minor releases even when they are breaking changes. Read the release notes before you deploy.

Moving from 13 or 14 to 16 is a migration. Next.js 15 requires React 19 and made params and searchParams asynchronous, so every page and layout that reads them changes. Custom middleware is also affected, since 16 renames it to proxy. Moving in two hops, 14 to 15 and then 15 to 16, lets you isolate what broke at each step. The trade-off is a longer calendar timeline.

You do not have to leave the Pages Router to fix these vulnerabilities. Keep the version upgrade and the App Router migration as separate projects: the upgrade closes the security gap, the migration restructures your app, and combining them makes it hard to tell which change broke what.

Should You Handle the Next.js Security Upgrade Internally or Get Help?

A version bump within 15.x or 16.x is work most teams can do alone. The upgrade is a dependency change, the advisories are public, and your existing test suite tells you whether it worked.

Outside help earns its cost on the 13/14-to-16 path when you have custom middleware carrying authorization logic, or a test suite too thin to catch a broken migration. In that case, the auth layer is the part to move carefully.

If your app sits in that second group, or you are not sure which group it falls into, talk to iSyncEvolution about a Next.js upgrade or security review.

Nextjs Security Vulnerabilities

FAQ

Is Next.js 14 Still Supported?

No. Next.js 14 reached end of life on October 26, 2025, and receives no security fixes. Upgrade to 15.5.27 or 16.3.8.

What Is the Next.js Middleware Bypass Vulnerability?

It is a class of 2026 advisories in which a crafted request reaches a protected route without middleware or proxy authorization checks applying. Vercel's May release patched several variants, and July added another affecting Turbopack builds with a single locale.

How Do I Know What Version of Next.js I'm Running?

Run next --version in your project, then confirm the resolved version in your lockfile. The lockfile reflects what is actually deployed.

How Often Does Next.js Release Security Patches?

Since July 2026, on a preannounced schedule, roughly monthly, plus out-of-band releases for critical issues such as the one on September 22.

What Did the September 30 Next.js Security Release Fix?

It fixed 7 vulnerabilities: 1 high-severity SSRF in Image Optimization, 5 medium and 1 low. Upgrade to 15.5.27 or 16.3.8. Version 16.3.7 does not include these fixes.

Nikhil Shah is the CTO and Co-Founder of iSyncEvolution, an engineering leader who aligns modern technology best practices with long-term commercial success. A veteran of cloud infrastructure and scalable web/mobile solutions, he specializes in building high-performance software environments. Nikhil helps global brands master their technical roadmaps, optimizing both code performance and development economics to fuel growth.

Recommended Blog