NewsJavaScriptSecurityWeb Development

Next.js October 14 Security Patch: Two Criticals Coming — Upgrade Now

Next.js security shield showing three waves of CVE patches in six weeks including sharp and undici upstream vulnerabilities
Next.js has seen three major security waves since September 2026

Vercel announced another out-of-band Next.js security patch landing October 14, 2026. Two Critical vulnerabilities and one High, this time in upstream dependencies. That makes three major security waves in six weeks, and if you haven’t upgraded to 16.3.8 yet, October 14 just became your hard deadline.

Three Waves in Six Weeks

The pattern is worth spelling out, because it changes how you should be thinking about Next.js versioning right now.

September 8: Two Critical patches dropped simultaneously. The first was a heap buffer overflow in libheif — the C library that sharp uses to decode AVIF images — triggering unauthenticated RCE through the Image Optimization API (CVSS 9.5). The second was a path traversal vulnerability that allowed unauthenticated code execution on Windows-hosted servers (CVSS 9.0), with no workaround available. Both fixed in 16.3.3.

September 23–30: A Critical RCE in next/og’s ImageResponse hit as an emergency out-of-band patch (16.3.6) — covered here — followed a week later by a High-severity SSRF in Image Optimization plus five more Medium and Low advisories covering cache poisoning, Draft Mode content leakage, and an information disclosure in the development server’s MCP endpoint. Fixed in 16.3.8 and 15.5.27.

October 14: Two Critical and one High in upstream dependencies. Details are embargoed until patch day — a sign of coordinated disclosure with upstream maintainers. The announcement from Vercel notes these fixes were “postponed from the September security release due to upstream coordination.”

What’s Being Patched: sharp and undici

Based on the pattern of previous patches and the upstream coordination language, the packages involved are sharp (Next.js’s image processing dependency) and undici (the HTTP/1.1 client bundled inside Node.js and used by Next.js internally).

sharp wraps libvips, which uses libheif for AVIF decoding — a deep native C dependency chain. It was already the vector for the September 8 AVIF RCE. Additional libheif vulnerabilities were disclosed in the weeks since, and sharp 0.35.5 addressed some of them. The October 14 update brings those upstream fixes into Next.js’s bundled version.

undici has accumulated several CVEs in October 2026 — WebSocket subprotocol handling issues (CVE-2026-19534), unbounded decompression leading to resource exhaustion, and unclean WebSocket close handling. Next.js bundles its own undici version, so upgrading Node.js alone does not fix these. You need a Next.js upgrade.

The Real Story: Upstream Dependency Supply Chain

Most of these vulnerabilities are not Next.js bugs — they’re bugs in C libraries deep in the dependency tree. libheif is C++. libvips is C. undici has its own independent security track record. The problem is that frameworks bundling complex native dependencies inherit every vulnerability in that chain, on a timeline governed by coordinated upstream disclosure. That’s why you see a six-week cluster instead of a single clean release.

This isn’t unique to Next.js — any framework bundling native image processing or custom HTTP clients carries this burden. The right response isn’t to switch frameworks. It’s to treat your framework version the same way you treat your OS: watch the security feed and patch fast.

What You Need to Do Before October 14

First, verify your actual deployed version — not what’s in package.json, but what’s in your lockfile and in production:

npm ls next
# or with pnpm
pnpm why next

If you’re below 16.3.8 (Active LTS) or 15.5.27 (Maintenance LTS), upgrade now. The September patches alone justify it. Also verify that sharp is at 0.35.4 or later if you use Image Optimization with remote or user-supplied URLs.

If your team is running Next.js 14.x or earlier, none of these patches apply to you — not because you’re safe, but because those versions are end-of-life. You’re carrying every unpatched CVE including the two unauthenticated RCEs from September. Upgrading to 16.x is not optional at this point. The Snyk vulnerability database for Next.js has the full picture.

On October 14 Itself

The full advisories — CVE numbers, affected version ranges, exact upgrade path — publish alongside the patch. Upgrade immediately when that happens. Assign someone now to watch the Next.js blog and GitHub releases that day.

Self-hosted deployments require manual action. Vercel-hosted apps receive many patches automatically at the platform level, but confirm your pinned next version gets updated if you have version constraints in your lockfile.

No active exploitation of the October 14 vulnerabilities has been reported at the time of writing — but historically, PoC exploits for Next.js RCEs have appeared within days of public disclosure. The track record on that has been consistent enough to plan around.

ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *

    More in:News