Skip to content

fix(deps): update dependency next to v16.3.8 [security] - autoclosed - #1252

Closed
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-next-vulnerability
Closed

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-next-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
next (source) 16.3.6 → 16.3.8 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Next.js has Server-Side Request Forgery in Image Optimization

CVE-2026-94483 / GHSA-cjq9-62q9-8jv4

More information

Details

Impact

An attacker-controlled, allow-listed remote URL can lead to server-side request forgery (e.g. to private IPs) during Image Optimization.

Workaround

Audit allow-listed remote URLs in images.remotePatterns (see https://nextjs.org/docs/app/getting-started/images#remote-images) for hosts that may not be trusted with their DNS entries. If no images.remotePatterns are configured, your app is not affected.

Severity

  • CVSS Score: 8.3 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Next.js has cache poisoning in SSG/ISR rendering that leads to cross-user content substitution and persistent denial of service

CVE-2026-94484 / GHSA-mcj8-r9mp-w47p

More information

Details

Next.js applications that use a root-level catch-all page together with statically generated or Incremental Static Regeneration routes can have their shared response cache poisoned by a single unauthenticated crafted request.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass

CVE-2026-94485 / GHSA-f87g-xv8r-7p7x

More information

Details

In Next.js App Router applications built with webpack, metadata image routes such as opengraph-image and twitter-image ignore the dynamicParams route segment option. An attacker can request metadata image URLs for dynamic segments that were deliberately excluded from generateStaticParams().

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Next.js has information disclosure in development server's Model Context Protocol endpoint

CVE-2026-94486 / GHSA-39w2-rjm5-chcv

More information

Details

The Next.js development server (next dev) exposes a Model Context Protocol endpoint that does not verify which website a request originates from, allowing a malicious website visited by the developer to read sensitive development data — including the project's location on disk, source code snippets from error reports, the route inventory, and development logs. Only applications run with next dev are affected. Production deployments do not serve this endpoint.

Severity

  • CVSS Score: 2.3 / 10 (Low)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Next.js has cache poisoning of SSG and ISR pages in self-hosted applications

CVE-2026-94543 / GHSA-4jqv-mc3x-m676

More information

Details

Self-hosted Next.js applications that use the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages can have a page's cache entry replaced with content from a different route, causing the affected page to serve wrong content to every visitor until the entry is revalidated. Applications deployed on Vercel are not affected.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Next.js: Pending use cache fill can leak Draft Mode content into regular responses and persisted pages

CVE-2026-94544 / GHSA-3w37-wq28-93x7

More information

Details

Pending use cache fills are shared across requests for the same key without distinguishing Draft Mode requests from regular requests. When two such requests overlap, the second request receives the first request's fill:

  • A regular request that overlaps an editor's Draft Mode request receives unpublished content, without any authentication.
  • A Draft Mode request that overlaps a regular request receives published content instead of the draft.

If the overlapping regular request prerenders a page — for example an on-demand prerender of a route that was not prerendered at build time — the unpublished content can be persisted into the generated page and served to all later visitors of that route until the page is revalidated. Since cached functions can be shared across routes, the poisoned page does not need to be the page the editor is previewing.

Sites are affected if they enable Cache Components (or experimental.useCache) and serve Draft Mode previews whose cached functions return draft-dependent content.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

vercel/next.js (next)

v16.3.8

Compare Source

This release contains security fixes for the following advisories:

High:

Medium:

Low:

v16.3.7

Compare Source

[!NOTE]
This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes
  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#​98931)
Credits

Huge thanks to @​lukesandberg for helping!


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 8, 2026
@renovate renovate Bot changed the title fix(deps): update dependency next to v16.3.8 [security] fix(deps): update dependency next to v16.3.8 [security] - autoclosed Oct 8, 2026
@renovate renovate Bot closed this Oct 8, 2026
@renovate
renovate Bot deleted the renovate/npm-next-vulnerability branch October 8, 2026 15:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants