Next.js 16.3.8 patches seven security bugs, with the top one letting an attacker reach private servers through the image optimizer
Next.js 16.3.8 patches a High-severity server-side request forgery in the image optimizer and six more advisories, including two cache poisoning bugs that affect self-hosted sites.
Image: GitHub
Why it mattersAny self-hosted Next.js site on the Pages Router or using root catch-all routes can serve one user's content to every visitor from a single crafted request, so upgrading is a same-day job rather than a sprint item.
Any self-hosted Next.js site is one crafted HTTP request away from serving the wrong user's content until the cache clears, and the fix went out on 30 September 2026 as version 16.3.8. The release bundles seven security advisories: one High and six Moderate, with a seventh Low issue in the development server. Sebastian Silbermann, who publishes on GitHub as eps1lon and works on the Next.js team, is the reporter on six of the seven.
The headline advisory is CVE-2026-94483, a server-side request forgery in the image optimizer that Vercel rates High at CVSS 8.3. In Vercel's description, "an attacker-controlled, allow-listed remote URL can lead to server-side request forgery (e.g. to private IPs) during Image Optimization". A site is affected only if it has set images.remotePatterns; sites that leave that config empty are not. For the sites that do set it, Vercel asks operators to check that every host on the allow-list is still a safe DNS target. The patched versions are 16.3.8 and 15.5.x.
The two cache poisoning bugs are the ones to read carefully
CVE-2026-94543 affects self-hosted sites on the Pages Router with statically generated or incrementally regenerated pages. The advisory says an attacker can "have a page's cache entry replaced with content from a different route, causing the affected page to serve wrong content to every visitor until the entry is revalidated". Sites deployed on Vercel's own platform are not affected. CVSS 6.3.
CVE-2026-94484 is a cache poisoning bug on the App Router. It affects self-hosted applications that combine a root-level catch-all page with static generation or ISR, and Vercel says a single unauthenticated crafted request can corrupt the response cache. Vercel calls out two outcomes: "cross-user content substitution and persistent denial of service". Patched in 16.3.8 and 15.5.x. CVSS 6.3.
The three other Moderate advisories cover information disclosure in App Router metadata image routes through a dynamicParams bypass, a Draft Mode content leak through pending use cache fills, and a cache leak across root params in nested use cache functions. The Low advisory is an information disclosure in the development server's Model Context Protocol endpoint, which only matters on a developer machine.
Six of the seven CVEs are credited to eps1lon in the advisory metadata, which means the Next.js team found them in its own code rather than through an external report. The advisory pages do not say what prompted the audit.
The practical reading, for a team running Next.js in production: if the site is on Vercel, the SSRF is the one to act on; if the site is self-hosted, the two cache poisoning bugs raise the ceiling of what one unauthenticated request can do to the whole user base. In both cases a point release is a same-day upgrade, because the gap between a patch landing and the first scanner hitting production is now short.
Source
The v16.3.8 release notes link each advisory on GitHub's security tab. The individual pages carry the CVSS scores and the exact affected version ranges: GHSA-cjq9-62q9-8jv4 for the SSRF, GHSA-4jqv-mc3x-m676 and GHSA-mcj8-r9mp-w47p for the two cache poisoning bugs.
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.

