Security Update: Critical Next.js vulnerability in ImageResponse
UpdateUnverifiedAdded Sep 24, 2026
The Next.js team has disclosed a critical severity vulnerability in an upstream dependency that can lead to remote code execution when ImageResponse renders untrusted input. It is patched in 15.5.26 and 16.3.6. Applications that do not pass untrusted input into ImageResponse are not expected to be affected. Here’s what Netlify customers need to know.
Topics: Streaming, Security, Pricing, Developer tools
More Netlify releases
Every Netlify release| Date | Release | Type |
|---|---|---|
| Sep 22 | Claude Opus 5.5 now available in AI Gateway and Agent Runnersunverified Update | Update |
| Sep 22 | GPT-6 Sol and GPT-6 Luna now available in AI Gateway and Agent Runnersunverified Update | Update |
| Sep 24 | New project activity feedunverified Preview | Preview |
| Sep 17 | TypeSafe Jev now available in AI Gatewayunverified Update | Update |
| Sep 15 | DeepSeek V4.1 Flash now available in AI Gatewayunverified Update | Update |
| Sep 14 | Agent Runners: Get a working result when low on creditsunverified Pricing | Pricing |
| Sep 11 | Social media share buttonsunverified Update | Update |
| Sep 10 | Cursor Origin now supported as a Git providerunverified Preview | Preview |
Also shipped on Sep 22, 2026
Netlify in September 2026Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.