Repository navigation
Update dependency next to v16.3.8 [SECURITY] - #568
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
Author
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
renovate
Bot
force-pushed
the
renovate/npm-next-vulnerability
branch
from
October 7, 2026 06:51
cafc5ff to
c178d87
Compare
renovate
Bot
force-pushed
the
renovate/npm-next-vulnerability
branch
from
October 8, 2026 09:19
c178d87 to
e9b31e6
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
16.3.6→16.3.8Next.js has Server-Side Request Forgery in Image Optimization
CVE-2026-94483 / GHSA-cjq9-62q9-8jv4
More information
Details
Impact
An attacker-controlled, allow-listed remote URL can lead to server-side request forgery (e.g. to private IPs) during Image Optimization.
Workaround
Audit allow-listed remote URLs in
images.remotePatterns(see https://nextjs.org/docs/app/getting-started/images#remote-images) for hosts that may not be trusted with their DNS entries. If noimages.remotePatternsare configured, your app is not affected.Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Next.js has cache poisoning in SSG/ISR rendering that leads to cross-user content substitution and persistent denial of service
CVE-2026-94484 / GHSA-mcj8-r9mp-w47p
More information
Details
Next.js applications that use a root-level catch-all page together with statically generated or Incremental Static Regeneration routes can have their shared response cache poisoned by a single unauthenticated crafted request.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass
CVE-2026-94485 / GHSA-f87g-xv8r-7p7x
More information
Details
In Next.js App Router applications built with webpack, metadata image routes such as opengraph-image and twitter-image ignore the
dynamicParamsroute segment option. An attacker can request metadata image URLs for dynamic segments that were deliberately excluded fromgenerateStaticParams().Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Next.js has information disclosure in development server's Model Context Protocol endpoint
CVE-2026-94486 / GHSA-39w2-rjm5-chcv
More information
Details
The Next.js development server (
next dev) exposes a Model Context Protocol endpoint that does not verify which website a request originates from, allowing a malicious website visited by the developer to read sensitive development data — including the project's location on disk, source code snippets from error reports, the route inventory, and development logs. Only applications run withnext devare affected. Production deployments do not serve this endpoint.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Next.js has cache poisoning of SSG and ISR pages in self-hosted applications
CVE-2026-94543 / GHSA-4jqv-mc3x-m676
More information
Details
Self-hosted Next.js applications that use the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages can have a page's cache entry replaced with content from a different route, causing the affected page to serve wrong content to every visitor until the entry is revalidated. Applications deployed on Vercel are not affected.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Next.js: Pending
use cachefill can leak Draft Mode content into regular responses and persisted pagesCVE-2026-94544 / GHSA-3w37-wq28-93x7
More information
Details
Pending
use cachefills are shared across requests for the same key without distinguishing Draft Mode requests from regular requests. When two such requests overlap, the second request receives the first request's fill:If the overlapping regular request prerenders a page — for example an on-demand prerender of a route that was not prerendered at build time — the unpublished content can be persisted into the generated page and served to all later visitors of that route until the page is revalidated. Since cached functions can be shared across routes, the poisoned page does not need to be the page the editor is previewing.
Sites are affected if they enable Cache Components (or
experimental.useCache) and serve Draft Mode previews whose cached functions return draft-dependent content.Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
vercel/next.js (next)
v16.3.8Compare Source
This release contains security fixes for the following advisories:
High:
Medium:
use cachefill can leak Draft Mode content into regular responses and persisted pagesLow:
v16.3.7Compare Source
Core Changes
Credits
Huge thanks to @lukesandberg for helping!
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.