Dev48
Language
  • About
  • Services
  • Industries
  • Technologies
  • Articles
  • Contacts
Book a call
    Home/Articles/Nextjs security update for a critical upstream issue
Dev48

© 2026 · All rights reserved.

Next.js Security Update for a Critical Upstream Issue

Источник: Next.js

Next.js Security Update for a Critical Upstream Issue

Source: Next.js

The September 22, 2026 out-of-band ecurity update for Next.j i now available

September 25, 2026

An out-of-band security update is now available in v16.3.6 (Active LTS) and v15.5.26 (Maintenance LTS). These releases upgrade upstream dependencies, including Satori, to address an issue that could lead to remote code execution in affected Next.js versions. Version 15.5.26 includes related hardening, but Next.js 15.x is not affected by the remote code execution issue.

Please patch your Next.js dependencies to maintain the security of your applications.

Impact

Remote Code Execution in Node.js ImageResponse (Critical Severity)

GHSA-vcvr-r3jv-pc5j (Next.js)

Related upstream advisory: GHSA-wx4j-mvgx-mqwp (Satori)

Next.js versions >=16.2.0 <16.3.6 are affected.

The issue affects the Node.js ImageResponse implementation in next/og. Under specific conditions, improper escaping in SVG output generated by Satori could lead to remote code execution due to vulnerabilities in other upstream dependencies. The fix upgrades those dependencies.

Applications using the Edge ImageResponse implementation are not affected.

Our security program

We work with a talented set of researchers to secure Next.js and other open source frameworks through Vercel's Open Source Bug Bounty. Anyone interested in contributing to the security of eligible frameworks is encouraged to participate there.

Any questions or concerns regarding our security programs or vulnerability management can be sent to security@vercel.com.

On this page

  • Impact
  • Remote Code Execution in Node.js ImageResponse (Critical Severity)
  • Our security program
← All articles

More in Software Development

All →
A new skill finds AI agent risks, fixes them, and proves the fix worked
Microsoft

A new skill finds AI agent risks, fixes them, and proves the fix worked

Some Supabase customers are publicly exposing reams of people’s data to the webПресса
Supabase

Some Supabase customers are publicly exposing reams of people’s data to the web

Blazor Basics: SEO Basics for Blazor Web Applications
Telerik

Blazor Basics: SEO Basics for Blazor Web Applications

Affected by layoffs? Don’t miss this $75 deal for your TechCrunch Disrupt 2026 Expo+ PassПресса
Expo

Affected by layoffs? Don’t miss this $75 deal for your TechCrunch Disrupt 2026 Expo+ Pass

Last 24 hours to save up to $200 on TechCrunch Disrupt 2026. Reason 5 of 5 to attend: MomentumПресса
Momentum

Last 24 hours to save up to $200 on TechCrunch Disrupt 2026. Reason 5 of 5 to attend: Momentum

We’re building Copilot as a new OS for work that spans every model, every form factor, and every task. Today, we’re announcing our biggest update to Copilot to date, bringing four things together [Read more]
Microsoft

We’re building Copilot as a new OS for work that spans every model, every form factor, and every task. Today, we’re announcing our biggest update to Copilot to date, bringing four things together [Read more]

More from Next.js

Upcoming Next.js September Security Release
Next.js

Upcoming Next.js September Security Release

Upcoming Next.js Security Update for a Critical Upstream Issue
Next.js

Upcoming Next.js Security Update for a Critical Upstream Issue

How we closed 1,500 GitHub issues in one month
Next.js

How we closed 1,500 GitHub issues in one month

How Turbopack chunks your JavaScript
Next.js

How Turbopack chunks your JavaScript