Skip to content
Nilay Kabariya

Entry No.054·Tested··4 min read

Next.js 16.3 vulnerabilities: which version is patched?

16.3.7 sounds patched, but npm audit still flags 6 advisories on it. Every 16.3.x step audited, plus why npm audit fix and next upgrade fail you.

by Nilay#nextjs#npm#securityTESTED

Verdict

16.3.0 carries 9 published advisories (3 critical) and 16.3.7 still carries 6, because the September 30 fixes skipped it. The upgrade built cleanly on every version I tried. The traps are in the tools: npm audit fix jumps you a minor version or does nothing at all, and next upgrade crashes on Windows.

Tested on

next
16.3.0, 16.3.7, 16.3.8, 16.4.0
npm
11.9.0
Node / OS
24.14.0 / Windows 11 Pro
Advisories
GitHub, as of Oct 8, 2026

✓ Re-verified on next 16.4.0, newest 16.3.x 16.3.8 (Linux): 4/4 checks still hold · results

Contents
  1. What npm audit says at each version01
  2. Which release fixed what02
  3. npm audit fix doesn’t do what you’d expect03
  4. next upgrade crashes on Windows04
  5. What’s new in 16.4.005
  6. What didn’t work06
  7. How this was tested07

Next.js has published a lot of security fixes since July, and the version numbers don’t make it obvious which release actually has them. The worst case is 16.3.7: it came out on September 29, the day before a scheduled security release, and it’s a bug-fix release only. Next.js’s own announcement says so.

So I took one small App Router app (an image, a server action, a next/og route and middleware: the features the advisories touch) and ran npm audit and next build on it at each step.

What npm audit says at each version

next npm audit for next Build
16.3.0 9 advisories: 3 critical, 1 high, 4 moderate, 1 low ✅ passes
16.3.7 6 advisories: 1 high, 4 moderate, 1 low ✅ passes
16.3.8 not flagged ✅ passes
16.4.0 (latest) not flagged ✅ passes

To stay on the 16.3 line, install the patched release:

npm i next@16.3

That resolved to 16.3.8. If you’re ready for the newer minor version, npm i next@latest gives you 16.4.0. Both builds of the test app passed with no new warnings.

The only warning on every version was one that has nothing to do with security: The "middleware" file convention is deprecated. Please use "proxy" instead. It’s printed on 16.3.0 too, so it isn’t something the upgrade added.

Which release fixed what

From the published advisories for the 16.3 line:

Released Patched in Fixed
Aug 25 16.3.3, 15.5.24 Two critical remote code execution bugs: one in the Image Optimization API with AVIF files, one on Windows-hosted servers
Sep 22 16.3.6, 15.5.26 A critical remote code execution bug in next/og’s ImageResponse
Sep 30 16.3.8, 15.5.27 Seven more: a high SSRF in Image Optimization, five medium (cache poisoning of SSG/ISR pages, use cache leaks, a metadata image route disclosure) and one low (the dev server’s MCP endpoint)

The September 30 announcement also says two more issues, one critical and one high, are “pending upstream coordination and will be addressed in a later Next.js release”. So today’s patched release won’t be the last one you need. npm audit can only flag what’s been published.

I tested the 16.x line only. The 15.x versions above come from the advisories.

npm audit fix doesn’t do what you’d expect

The obvious fix behaved differently depending on how next was written in package.json:

package.json had npm audit fix result
"next": "^16.3.0" Installed 16.4.0, a new minor version, not the 16.3 patch release. package.json unchanged.
"next": "16.3.0" (exact) Did nothing. Printed fix available via npm audit fix --force.
exact, then npm audit fix --force Installed 16.4.0 and rewrote the pin to ^16.4.0.

The exact pin isn’t unusual: create-next-app@16.3.0 writes "next": "16.3.0" exactly. So on a freshly scaffolded project, npm audit fix leaves every advisory in place, and the forced version quietly removes the pin you had. npm update next on a caret range also went to 16.4.0.

next upgrade crashes on Windows

Next.js has its own upgrade command, and on Windows it failed immediately, from PowerShell and from Git Bash:

$ npx next upgrade --revision 16.3.8
Error: spawn npx ENOENT
    at onErrorNT (node:internal/child_process:484:16)
  ...
  spawnargs: [ '--yes', '@next/codemod@canary', 'upgrade', '16.3.8' ]

It’s reported upstream (vercel/next.js#97980). The fix (#98075) was still unmerged when I tested, and 16.4.0’s next upgrade crashed the same way.

Run the command next upgrade tries to launch, directly:

npx --yes @next/codemod@canary upgrade 16.3.8

What’s new in 16.4.0

16.4.0 came out on October 6. From its release notes: next dev and next build now nudge you when your version has known security issues, next upgrade --ai adds vulnerability coverage, and the Pages Router deprecates React 18. I only built the test app on it (it passed); I didn’t test the nudges or the AI upgrade.

What didn’t work

How this was tested

One App Router app (TypeScript, next/image, a server action, a next/og route, a middleware file) on Windows 11 with Node 24.14.0 and npm 11.9.0. For each of next 16.3.0, 16.3.7, 16.3.8 and 16.4.0: npm audit --json (counting the advisories listed under next) and next build (Turbopack). Then npm audit fix, npm audit fix --force, npm update next and a direct install of the 16.3 line, each starting again from 16.3.0, with both caret and exact versions in package.json. Severities and counts are npm’s on October 8, 2026, and will change as new advisories are published. I didn’t test the vulnerabilities themselves, the Pages Router, custom servers or the 15.x line.

The code for every case above is public, so you can run it yourself: next-security in nk-repro.

— N.K., end of entry No.054

Useful? Pass it on:Post on XFollow @EmotionalMatter

Related entries

  1. No.039

    npm 12 breaking changes, tested: what actually breaks

    The headline change, install scripts blocked by default, broke puppeteer, cypress, sqlite3 and Claude Code's npm package, and silently skipped lefthook's git hooks. esbuild, bcrypt, sharp and better-sqlite3 kept working. Every install reported success, and the only sign was a warning after the summary.

    TESTED5 min
  2. No.031

    TypeScript 7 migration guide: breaking changes, tested

    Every option TypeScript 6.0.3 marked as deprecated was a hard error on 7.0.2, and ignoreDeprecations no longer silences it. Two defaults that arrived in 6.0 (strict on, @types not loaded automatically) also break projects coming straight from 5.9.

    TESTED6 min
  3. No.030

    Does Next.js, Angular, Vue or NestJS work with TypeScript 7?

    Next.js 16.3.6 built and type-checked on plain TypeScript 7.0.2. Angular 22.2, Vue with vue-tsc 3.3 and NestJS 12 all failed, and all three built again on Microsoft's side-by-side setup, with tsc still on 7.0.2. Nuxt, Svelte and Astro still built on 7, but their type-check commands refused it until TypeScript 6 was installed alongside.

    TESTED5 min

Post card · Newsletter

Get the next fix in your inbox.

One short email when a new entry is published. No spam, never shared, and you can leave any time.

— Nilay

or follow by RSSor on X

By subscribing you agree to the privacy note. One click to leave.

tip: paste the exact error text