Security Update: Multiple vulnerabilities in Next.js
Update3 days agoUnverifiedAdded Oct 2, 2026
The Next.js team has disclosed seven security vulnerabilities in Next.js (one high, five medium, one low), patched on September 30, 2026 in 15.5.27 and 16.3.8. The issues span server-side request forgery (SSRF), cache poisoning, and information disclosure. Several of them do not affect apps hosted on Netlify. Here's what Netlify customers need to know.
Topics: Security, Developer tools
More Netlify releases
Every Netlify release| Date | Release | Type |
|---|---|---|
| Sep 303 days ago | Update | Update |
| Sep 303 days ago | Trust Center is now in the Netlify Dashboard unverified Update | Update |
| Sep 294 days ago | Rich link previews for Agent Runners sites unverified Preview | Preview |
| Sep 294 days ago | Update | Update |
| Sep 285 days ago | Preview | Preview |
| Sep 285 days ago | Update | Update |
| Sep 249 days ago | New project activity feed unverified Preview | Preview |
| Sep 2211 days ago | Update | Update |
Also shipped on Sep 30, 2026
Netlify in September 2026| Date | Company | Release | Product | Type |
|---|---|---|---|---|
| Sep 303 days ago | New Relic | Preview | ||
| Sep 303 days ago | New Relic | Preview | ||
| Sep 303 days ago | Astro | Preview | ||
| Sep 303 days ago | The Astro IDE is generally available unverified | Astro | GA | |
| Sep 303 days ago | Cloudflare developer platform | Beta | ||
| Sep 303 days ago | Cloudflare developer platform | Beta |