Advisories in the release: 7 (Source: Next.js (Vercel) security release post (September 30, 2026))
A cache is a promise. It says two visitors asked the same question, so both can get the same saved answer. The Next.js security release of September 30 shows what happens when that promise breaks. Most of the time the site does not crash; it hands saved content to people who were never meant to see it.
What Next.js released
Vercel maintains Next.js. It published patches for two supported lines: version 16.3.8 and version 15.5.27. The first is the active long-term-support line. The second is in maintenance.
The post also says one fix for a critical flaw and one for a high-severity flaw had been delayed. The cause was slow updates in upstream dependencies, meaning code Next.js builds on. Vercel says those fixes are now available.
The seven advisories in the post are rated one high, five medium and one low. None is rated critical. The post does not explain how this fits with its mention of a delayed critical fix. We will not guess which item that refers to. All severity labels are Vercel's own.
Four flaws, one pattern
Four of the seven advisories involve caches. In each, saved content can appear where it does not belong. Here is how each works, according to Vercel.
First, take self-hosted apps that use the Pages Router with static or regularly refreshed pages. One page's saved entry can be overwritten with content from another route. Every visitor then sees the wrong content until the entry is refreshed. Apps deployed on Vercel are not affected.
Second, some apps have a root-level catch-all page plus static or refreshed routes. A single crafted request, with no login, can corrupt their shared response cache.
The advisory list has a matching entry for this kind of cache poisoning. It adds a second harm: a lasting denial of service. That means the service stays unusable for real users. Vercel does not spell out the link, so treat the match as our reading.
Third, take apps with Cache Components turned on. One cached function can call another that reads a root parameter. The outer function's cache key then leaves that parameter out. So a visitor can receive the version built for a different parameter value. Vercel says an attacker cannot choose which values leak.
Fourth, the cache shares in-progress work across requests. It does not separate editor previews, called Draft Mode, from normal traffic. A normal request that overlaps an editor's preview can receive unpublished content. No login is needed.
If that normal request builds a page ahead of time, the draft can be baked into the page. Later visitors then see it until the page is refreshed.
What this shows about speed features
Caching exists to skip work. To skip work safely, the system must know when two requests are truly the same. That rule is a trust decision. It lives in a cache key that is easy to overlook in review.
Picture an editor previewing an unpublished page. The draft might hold a price change or an announcement that is not ready. In the fourth flaw, the request that sees it needs no authentication.
The conditions are narrow. Vercel says a site is affected only if it turns on Cache Components or experimental.useCache. The site must also run editor previews where cached functions return draft-specific content. Sites without that setup are outside this flaw.
The other three fixes
The image optimization flaw is the one rated high. Suppose an attacker controls an image address that the app's allow-list already permits. The server can then be pushed to fetch internal addresses, such as private IP ranges. In plain terms, the server can be tricked into making requests inside the company network. Apps with no images.remotePatterns set are not affected.
The metadata image flaw hits App Router apps built with webpack. Next.js uses special routes to produce the preview pictures shown when a page is shared on social networks. Two examples are opengraph-image and twitter-image. In these builds, those routes do not respect a team's limit on which dynamic pages may exist. An attacker can request pictures for pages the team deliberately left off its pre-build list, generateStaticParams(). Turbopack builds are not affected.
The third flaw is rated low, but it concerns developer habits. Running a project with next dev opens a Model Context Protocol endpoint. That is a standard way for AI tools to connect to software. The endpoint did not check which website was calling it.
A malicious site visited by the developer could read the project's location on disk. It could also read code snippets from error reports, the route list and development logs. Production deployments do not serve this endpoint.
This is one flaw in one framework, not a trend. It is still a fair reminder. Tools built for AI assistants run on developer laptops. They need the same origin checks as any web service.
How common Next.js is among large sites
WebPulse scanned the Tranco top 10,000 domains in September 2026. Of 7,064 that responded, a platform was detected on 2,491. Next.js accounted for 791 of those.
This is a sample of detected platforms. It is not a count of vulnerable sites. The scan cannot see version, hosting model or settings. Those details decide whether a site is exposed.
Questions to put to your team
Ask which Next.js version each production app runs. Is it 16.3.8, 15.5.27 or later?
Ask which apps are self-hosted and use Pages Router static or refreshed pages. Ask which use Cache Components or experimental.useCache with Draft Mode previews.
Ask whether images.remotePatterns is set, and which hosts it allows. Ask which builds use webpack rather than Turbopack.
Ask whether developers run next dev while browsing other sites. Also ask whether anyone tests that one user's content cannot appear for another.
A fast page is only a good page if it is the right page. Caching decisions deserve the same review as login decisions.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Next.js (Vercel).





