Skip to main content

Next.js 16.3.8

Release Date: September 30, 2026

Security-Focused Release

Next.js 16.3.8, published September 30, 2026, is a security patch release that fixes seven advisories across the framework. The update is strongly recommended for any production deployment, especially self-hosted applications and those using image optimization or the App Router metadata system.

High Severity Advisory

The most serious fix addresses a Server-Side Request Forgery (SSRF) vulnerability in Image Optimization (GHSA-cjq9-62q9-8jv4). Image optimization endpoints could be abused to make the server issue requests to arbitrary destinations, which has real consequences for applications that pass user-influenced image URLs.

Medium Severity Fixes

Five medium-severity issues are resolved. These include an information disclosure in App Router metadata image routes via a dynamicParams bypass, and a cluster of cache-related defects: cache poisoning of SSG and ISR pages in self-hosted apps, cross-user content substitution and persistent denial of service through SSG/ISR cache poisoning, a pending use cache fill leaking Draft Mode content into regular responses, and a cache leak across root param values in nested use cache functions.

Low Severity and Summary

A low-severity advisory covers an information disclosure in the development server Model Context Protocol (MCP) endpoint. No new features land in 16.3.8, so the decision to upgrade is straightforward: patch now to close these vulnerabilities. Standard package manager update commands will bring you in line, and no breaking configuration changes accompany the release.

Other Versions

By continuing to use the site, you agree to the use of cookies.