Next.js 16.3.8
Security-Focused Release
Next.js 16.3.8, published September 30, 2026, is a security patch release that fixes seven advisories across the framework. The update is strongly recommended for any production deployment, especially self-hosted applications and those using image optimization or the App Router metadata system.
High Severity Advisory
The most serious fix addresses a Server-Side Request Forgery (SSRF) vulnerability in Image Optimization (GHSA-cjq9-62q9-8jv4). Image optimization endpoints could be abused to make the server issue requests to arbitrary destinations, which has real consequences for applications that pass user-influenced image URLs.
Medium Severity Fixes
Five medium-severity issues are resolved. These include an information disclosure in App Router metadata image routes via a dynamicParams bypass, and a cluster of cache-related defects: cache poisoning of SSG and ISR pages in self-hosted apps, cross-user content substitution and persistent denial of service through SSG/ISR cache poisoning, a pending use cache fill leaking Draft Mode content into regular responses, and a cache leak across root param values in nested use cache functions.
Low Severity and Summary
A low-severity advisory covers an information disclosure in the development server Model Context Protocol (MCP) endpoint. No new features land in 16.3.8, so the decision to upgrade is straightforward: patch now to close these vulnerabilities. Standard package manager update commands will bring you in line, and no breaking configuration changes accompany the release.