The Next.js team has disclosed a critical severity vulnerability in an upstream dependency that can lead to remote code execution when ImageResponse renders untrusted input. It is patched in 15.5.26 and 16.3.6. Applications that do not pass untrusted input into ImageResponse are not expected to be affected. Here’s what Netlify customers need to know. Vulnerabilities
Continue reading...
- GHSA-vcvr-r3jv-pc5j / CVE-2026-94545 — Remote Code Execution in next/og ImageResponse. Critical. Patched in 15.5.26 and 16.3.6.
- next 15.5.26 or later, or 16.3.6 or later, then redeploy.
- Next.js security advisory (GHSA-vcvr-r3jv-pc5j)
- Next.js Security Update for a Critical Upstream Issue
- Next.js security advisories
Continue reading...