Skip to main content

Security Update: Multiple vulnerabilities in Next.js

By Steven Van ·

Netlify says three of the seven Next.js flaws do not affect its sites; the rest need an upgrade to 15.5.27 or 16.3.8 and adapter 5.16.1.

The Next.js team has patched seven vulnerabilities (one high, five medium, one low) in versions 15.5.27 and 16.3.8, and Netlify has published guidance on which ones reach sites hosted on Netlify. The issues cover server-side request forgery (SSRF), cache poisoning and information disclosure.

Three are not a problem on Netlify:

  • Image optimizer SSRF (high): image optimization runs on Netlify Image CDN, a separate service, so the vulnerable Next.js code path is not used.
  • Draft Mode use cache leak: it needs two requests to share one server process, and each request on Netlify runs in its own isolated invocation.
  • Development MCP disclosure: it only affects next dev, and Netlify serves production builds.

The others do apply:

  • Metadata image dynamicParams bypass: affects Webpack builds on Netlify, not Turbopack builds.
  • Cross-route cache poisoning (SSG/ISR): affects Pages Router apps with SSG/ISR and a root catch-all route.
  • Encoded paths and /index: App Router apps with a prerendered catch-all route can return an HTTP 500 for certain valid percent-encoded URLs.
  • Cache leak across root param values: affects Next.js 16.x apps using Cache Components with a nested use cache that reads root params, such as locale or region.

Netlify recommends upgrading next to 15.5.27 or 16.3.8 and redeploying. The Netlify adapter also needs to be at @netlify/plugin-nextjs 5.16.1. It installs automatically by default, so a redeploy picks it up, and only sites that pin the version need a manual upgrade. Without the adapter update, prerendered pages miss the cache and re-render, which is a performance regression rather than a security one. Netlify says public deploy previews and branch deploys may stay vulnerable until they are automatically deleted, and suggests deleting them manually.

Netlify
Netlify
Lightning-fast web platform for deploying, hosting, and scaling modern sites — one-click deploys from Git or any modern AI builder.
View Netlify →

Read the original announcement →

Read Security Update: Multiple vulnerabilities in Next.js on Creators Toolbox