Vercel's September 30 security release patches seven vulnerabilities across Next.js 16.3.8 and 15.5.27, but the most dangerous bugs — a critical and a high-severity issue — are still unpatched pending upstream coordination.
If you're running any Next.js 15.x or 16.x app in production, this release demands attention this week: the fixes include a high-severity SSRF in Image Optimization that can reach your cloud metadata endpoints, plus five medium-severity caching and information disclosure bugs that quietly erode your app's security posture. Here's what got patched, what didn't, and exactly how to close the gap.
What's in the Release
Vercel published Next.js 16.3.8 and 15.5.27 on September 30, 2026, as a scheduled security release announced a week earlier. The breakdown: one high-severity vulnerability, five medium, and one low.
The headliner is an SSRF (server-side request forgery) bug in Next.js Image Optimization. If your next.config.js includes remotePatterns (or the older domains config) to allow fetching external images, an attacker can craft a URL that tricks the optimizer into making requests to private IP ranges. CODERCOPS's analysis of the release notes this means cloud metadata endpoints and internal services become reachable from the outside. If you're running on AWS, GCP, or Azure VMs, that metadata endpoint is a direct path to instance credentials.
The five medium-severity fixes address:
- Four caching-related vulnerabilities, including SSG/ISR cache poisoning that could let attackers serve stale or manipulated content to users
- An information disclosure bug in App Router metadata image routes that could leak data through the way Next.js generates Open Graph and Twitter Card images
The single low-severity fix targets the dev server's MCP (Model Context Protocol) endpoint, which is less urgent for production but still worth patching in development environments.
A Note on What's Missing
The original advance notice on September 23 promised nine fixes, including one critical-severity vulnerability and two high-severity ones. By release day, that count dropped to seven. Vercel's blog states the remaining critical and one high issue are "pending upstream coordination" and will ship in a future release. That phrasing strongly suggests the bugs live in a dependency — likely React itself — and Vercel can't unilaterally patch them.
This matters for your risk calculus. Upgrading to 16.3.8 is necessary but not sufficient. A second patch is coming, and the outstanding critical vulnerability should keep your team on alert for the follow-up release.
The SSRF in Image Optimization: How It Works
Next.js Image Optimization is one of the framework's most-used features. You drop in <Image src="https://cdn.example.com/photo.jpg" />, configure remotePatterns, and Next.js fetches, resizes, and caches the image server-side. It's convenient and performant. It's also a proxy, and proxies are attack surface.
The SSRF vulnerability works like this: an attacker supplies a URL that resolves to a private IP address, but the hostname belongs to an allow-listed domain. If your remotePatterns config uses a broad wildcard like https://**.example.com/**, any subdomain that permits user content or redirects can be weaponized. The optimizer dutifully fetches the resource, and now your server has made a request to 169.254.169.254 (or whatever internal address the attacker targeted).
Affected versions: 16.3.x before 16.3.8, and 15.5.x before 15.5.27.
Mitigation Beyond the Patch
Upgrading to Next.js 16.3.8 fixes the SSRF, but you should also tighten your remotePatterns while you're in the config file. Replace broad wildcards with pinned hostnames:
// Before — too broad
remotePatterns: [
{ protocol: 'https', hostname: '**.example.com' }
]
// After — pinned
remotePatterns: [
{ protocol: 'https', hostname: 'cdn.example.com' }
]
If you're on a cloud VM, confirm your instance metadata service uses IMDSv2 (on AWS) or equivalent protections. The SSRF patch stops the request at the framework level, but defense in depth means your infrastructure shouldn't trust those requests either.
The Broader Security Context: CVE-2025-55182 and React RCE
This release doesn't exist in isolation. Earlier this year, Next.js and React dealt with a critical remote code execution vulnerability in React Server Components, tracked as CVE-2025-55182. That bug affected React 19.0.0 through 19.2.0 and, by extension, Next.js 15.x and 16.x apps using the App Router. As documented in the GitHub security advisory, the fix for CVE-2025-55182 required upgrading both React (to 19.0.1, 19.1.2, or 19.2.1) and Next.js to specific patched versions.
That RCE was a wake-up call. Server Components execute on the server by design, which means a code execution vulnerability in that layer gives attackers the same access as your backend. The September release's outstanding critical vulnerability — the one still pending upstream coordination — sits in this same risk neighborhood. We don't know the exact vector yet, but the "upstream" language and the precedent of CVE-2025-55182 suggest React's server-side rendering pipeline remains an active area of security research.
Our earlier reporting on emerging AI trends for developers noted that the shift toward server-side execution models, including edge computing and server components, concentrates more logic (and more risk) on the backend. Frameworks like Next.js that blur the client-server boundary need to be especially rigorous about what runs where and who can trigger it.
How to Upgrade
The upgrade path is straightforward. For Next.js 16.x apps:
npm install next@16.3.8
For teams still on 15.x:
npm install next@15.5.27
After upgrading, verify the installed version:
npx next --version
One important detail: Next.js 16.3.7 shipped on September 29 as a regular bug fix release. It contains none of the security patches. If your CI/CD pipeline auto-updated to 16.3.7 between September 29 and 30, you need to bump again. Check your lockfile.
Verification Checklist
After deploying the upgrade:
- Confirm the version in your deployment logs or health endpoint
- Test Image Optimization with your existing
remotePatternsto ensure nothing broke - Review your
remotePatternsconfig and narrow any overly broad wildcards - Check for the follow-up release — subscribe to Vercel's security blog or watch the Next.js releases page on GitHub for the patch addressing the remaining critical and high vulnerabilities
- Audit your React version — if you haven't already patched CVE-2025-55182, do that now too
What Comes Next
The two unpatched vulnerabilities are the elephant in the room. Vercel has been transparent about the delay, which is the right call — shipping a partial fix for a dependency bug could create worse problems than waiting for coordinated disclosure. But it means every Next.js production app is currently carrying known, unpatched risk at the critical severity level.
There's no public timeline for the follow-up release, so watch for it and treat it with the same urgency as this one.
For now, upgrade to 16.3.8 (or 15.5.27), tighten your image optimization config, and make sure your React packages are current. The September release closes real attack vectors. The next one will close bigger ones.