Skip to content

Update dependency next to v16.3.8 [SECURITY] - #568

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-next-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-next-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
next (source) 16.3.6 → 16.3.8 age confidence

Next.js has Server-Side Request Forgery in Image Optimization

CVE-2026-94483 / GHSA-cjq9-62q9-8jv4

More information

Details

Impact

An attacker-controlled, allow-listed remote URL can lead to server-side request forgery (e.g. to private IPs) during Image Optimization.

Workaround

Audit allow-listed remote URLs in images.remotePatterns (see https://nextjs.org/docs/app/getting-started/images#remote-images) for hosts that may not be trusted with their DNS entries. If no images.remotePatterns are configured, your app is not affected.

Severity

  • CVSS Score: 8.3 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Next.js has cache poisoning in SSG/ISR rendering that leads to cross-user content substitution and persistent denial of service

CVE-2026-94484 / GHSA-mcj8-r9mp-w47p

More information

Details

Next.js applications that use a root-level catch-all page together with statically generated or Incremental Static Regeneration routes can have their shared response cache poisoned by a single unauthenticated crafted request.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass

CVE-2026-94485 / GHSA-f87g-xv8r-7p7x

More information

Details

In Next.js App Router applications built with webpack, metadata image routes such as opengraph-image and twitter-image ignore the dynamicParams route segment option. An attacker can request metadata image URLs for dynamic segments that were deliberately excluded from generateStaticParams().

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Next.js has information disclosure in development server's Model Context Protocol endpoint

CVE-2026-94486 / GHSA-39w2-rjm5-chcv

More information

Details

The Next.js development server (next dev) exposes a Model Context Protocol endpoint that does not verify which website a request originates from, allowing a malicious website visited by the developer to read sensitive development data — including the project's location on disk, source code snippets from error reports, the route inventory, and development logs. Only applications run with next dev are affected. Production deployments do not serve this endpoint.

Severity

  • CVSS Score: 2.3 / 10 (Low)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Next.js has cache poisoning of SSG and ISR pages in self-hosted applications

CVE-2026-94543 / GHSA-4jqv-mc3x-m676

More information

Details

Self-hosted Next.js applications that use the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages can have a page's cache entry replaced with content from a different route, causing the affected page to serve wrong content to every visitor until the entry is revalidated. Applications deployed on Vercel are not affected.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Next.js: Pending use cache fill can leak Draft Mode content into regular responses and persisted pages

CVE-2026-94544 / GHSA-3w37-wq28-93x7

More information

Details

Pending use cache fills are shared across requests for the same key without distinguishing Draft Mode requests from regular requests. When two such requests overlap, the second request receives the first request's fill:

  • A regular request that overlaps an editor's Draft Mode request receives unpublished content, without any authentication.
  • A Draft Mode request that overlaps a regular request receives published content instead of the draft.

If the overlapping regular request prerenders a page — for example an on-demand prerender of a route that was not prerendered at build time — the unpublished content can be persisted into the generated page and served to all later visitors of that route until the page is revalidated. Since cached functions can be shared across routes, the poisoned page does not need to be the page the editor is previewing.

Sites are affected if they enable Cache Components (or experimental.useCache) and serve Draft Mode previews whose cached functions return draft-dependent content.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

vercel/next.js (next)

v16.3.8

Compare Source

This release contains security fixes for the following advisories:

High:

Medium:

Low:

v16.3.7

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#​98931)
Credits

Huge thanks to @​lukesandberg for helping!


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from wereHamster as a code owner October 1, 2026 15:10
@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 1, 2026
@renovate

renovate Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
Error: ERR_PNPM_STRICT_MIN_RELEASE_AGE_REQUIRES_SAVE

  × updating dependencies
  ╰─▶ minimumReleaseAgeStrict cannot be combined with --no-save: approval
      would require writing to minimumReleaseAgeExclude in pnpm-
      workspace.yaml, which --no-save prevents.
  help: Drop --no-save so the exclude list can be persisted, or set
        minimumReleaseAgeStrict: false.


@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
swiss-maps Ready Ready Preview Oct 8, 2026 9:20am UTC

Request Review

@renovate
renovate Bot force-pushed the renovate/npm-next-vulnerability branch from c178d87 to e9b31e6 Compare October 8, 2026 09:19
@renovate renovate Bot changed the title Update dependency next to v16.3.6 [SECURITY] Update dependency next to v16.3.8 [SECURITY] Oct 8, 2026

This branch was successfully deployed

1 active deployment
Preview — e9b31e6c Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants