Skip to content

Security Update: Multiple vulnerabilities in Next.js

Update3 days agoUnverifiedAdded Oct 2, 2026

The Next.js team has disclosed seven security vulnerabilities in Next.js (one high, five medium, one low), patched on September 30, 2026 in 15.5.27 and 16.3.8. The issues span server-side request forgery (SSRF), cache poisoning, and information disclosure. Several of them do not affect apps hosted on Netlify. Here's what Netlify customers need to know.

Topics: Security, Developer tools

Netlify's release notes

More Netlify releases

Every Netlify release
DateRelease
Sep 303 days ago
Update
Sep 303 days ago
Update
Sep 294 days ago
Preview
Sep 294 days ago
Update
Sep 285 days ago
Preview
Sep 285 days ago
Update
Sep 249 days ago
Preview
Sep 2211 days ago
Update

Also shipped on Sep 30, 2026

Netlify in September 2026

New releases by email

Tuesday mornings: the week's data, AI and developer-tools releases, only in weeks when something shipped.

Double opt-in. Unsubscribe any time.