Skip to content
Putting technology to work.
Insights to guide decisions and action.

Search articles

Does the September Next.js vulnerability affect you? Checking next/og and Windows deployments

Table of contents · 7 items

npm audit reported "critical" for next, or a vendor asked you, "About the Next.js vulnerability, is your site affected?" Both Next.js advisories published in September 2026 are remote code execution (RCE) issues rated CRITICAL. However, the conditions for being affected are "how you generate OG images" and "the server's OS," and the advisories state that even if your version falls within the range, you are not affected unless the code or hosting conditions are met.

We read the advisory text, the fix commits and the Next.js documentation, and lay out the steps to decide whether your app is affected. We also show the results of npm audit in our test environment (Linux, Node.js v22.22.0, npm 10.9.4). We did not reproduce the attacks.

The two September advisories have completely different conditions

Here are the two advisories as recorded in the GitHub Advisory Database.

ImageResponse in next/ogServers on Windows
IDGHSA-vcvr-r3jv-pc5jGHSA-p293-qw3h-jr36(CVE-2026-75604)
Published dateSeptember 30, 2026September 8, 2026
Affected versions16.2.0 or later and earlier than 16.3.613.4.0 or later and earlier than 15.5.24; 16.0.0 or later and earlier than 16.3.3
Conditions for being affectedPassing attacker-controllable values to SVG content, attributes or styles in the Node.js version of ImageResponseRunning the server on a Windows file system (Pages Router or App Router without Cache Components)
WorkaroundDo not pass external values (stated in the advisory)None. Update immediately if on Windows

There is one more advisory, published on September 8, about AVIF image optimization (GHSA-2xp9-vwfh-vxw4, with the same fixed versions, 15.5.24 and 16.3.3). This one is an issue in sharp and libheif, which image optimization uses, and we cover it in how to check for the sharp and libheif AVIF vulnerability.

next/og: are you putting values from outside into images on Node.js?

ImageResponse in next/og is a feature that generates images such as per-article OGP images from JSX and CSS. According to the documentation, it uses @vercel/og, Satori and Resvg internally to convert them to PNG.

According to the advisory, the Node.js version of ImageResponse is affected by an upstream vulnerability that could lead to RCE. Apps that pass attacker-controllable values to SVG content, attributes or styles are affected; apps that use the Edge version, and apps that do not pass such values, are not.

Whether the Node.js or Edge version runs is determined by the route's runtime. In the package code for Next.js 16.3.6, if NEXT_RUNTIME is edge, the Edge version of @vercel/og is loaded; otherwise the Node.js version is. The documentation says the default value of runtime is 'nodejs', and 'edge' is deprecated. In other words, opengraph-image.tsx files and Route Handlers that do not specify runtime at all run on the Node.js version.

The fixes are Satori's September 22, 2026 commit "fix: Harden SVG serialization" (tag 0.33.5, adding value escaping and validation of XML names and inline styles) and a Next.js commit from the same day, "Harden next/og SVG serialization" (patching the bundled @vercel/og 0.11.1); the latter is included in 16.3.6.

We covered the main changes in Next.js 16.3 in memory improvements to the Next.js 16.3 development server. Every version from 16.2.0 onward falls within this range, so even apps that only recently moved to the 16.3 line should confirm they are on 16.3.6 or later.

Search commands to check your code

From here on is our editorial team's proposal. Running the following searches at the root of your repository narrows down the files you need to check (behavior confirmed against test files in our test environment).

# 1. next/og(または @vercel/og)を読み込んでいるファイル
grep -rlE "from ['\"](next/og|@vercel/og)['\"]" \
  --include='*.ts' --include='*.tsx' --include='*.js' --include='*.jsx' --include='*.mjs' \
  --exclude-dir=node_modules --exclude-dir=.next .

# 2. 画像を生成するファイル規約(opengraph-image / twitter-image / icon / apple-icon)
find . \( -path ./node_modules -o -path ./.next \) -prune -o -type f \
  \( -name 'opengraph-image.*' -o -name 'twitter-image.*' -o -name 'icon.*' -o -name 'apple-icon.*' \) -print

# 3. ランタイムを明示しているファイル
grep -rnE "runtime\s*[:=]\s*['\"](edge|experimental-edge|nodejs)['\"]" \
  --include='*.ts' --include='*.tsx' --include='*.js' --include='*.jsx' \
  --exclude-dir=node_modules --exclude-dir=.next .

Treat any file for which the third search did not return export const runtime = 'edge', or export const config = { runtime: 'edge' } for the Pages Router, as running on the Node.js version (we confirmed in the 16.3.6 build code that config.runtime is read for the Pages Router).

Our editorial team's diagram of a decision flow that narrows down files using next/og in three steps: whether the runtime is Node.js, whether external values are passed to the image, and whether the Next.js version is 16.2.0 or later and earlier than 16.3.6, prioritizing an update when all three apply

The diagram is our editorial team's arrangement of the advisory's conditions in the order you would check them. "External values" means things like params derived from the URL path, search parameters, and titles or names submitted by users. The advisory's example puts values into SVG elements, but because ImageResponse turns the whole JSX into SVG before rendering the image, our editorial team recommends treating values placed anywhere in the JSX the same way until you update. Even images that use only your own values may later gain a submission feature. If you are on an affected version, upgrading to 16.3.6 or later is more reliable than narrowing down the conditions.

Windows: where it runs matters more than the code

For GHSA-p293-qw3h-jr36, the condition is the server's OS rather than how the code is written. The advisory says that Pages Router or App Router apps that do not use Cache Components could be exposed to RCE when the server runs on a machine using a Windows file system, and since there is no workaround, it asks you to update immediately. The fix commit is titled "Fix ISR misses with backslashes in segments when deployed on Windows," and it changes the code that saves the ISR cache to files.

What to check is the OS of the machine running the Next.js server in production. Setups running on Windows Server or Windows virtual machines are candidates. If a vendor operates it, have them answer in writing with the OS and Next.js version, and if the OS is unknown, assume you are affected and prioritize the update.

The fixed versions 15.5.24 and 16.3.3 were published to npm on August 25, 2026, before the advisory was published (September 8). If you updated at the end of August or later, this issue is resolved. We covered how to decide who updates within the scope of a maintenance contract in Abandoned React2Shell sites and reviewing maintenance contracts.

What npm audit shows and what it doesn't

In our test environment, we created a package.json with only next and react / react-dom (19.2.0) as dependencies, then ran npm audit --json after npm install --package-lock-only (October 1, 2026).

next versionNext.js advisories reported by npm audit
16.3.23: GHSA-p293 (Windows), GHSA-2xp9 (AVIF), GHSA-vcvr (next/og)
16.3.51: GHSA-vcvr (next/og)
16.3.6 / 16.3.8None (0 findings)
15.5.232: GHSA-p293, GHSA-2xp9 (plus findings for the bundled postcss and sharp)
15.5.27No advisories for Next.js itself. The finding for the bundled postcss remains

npm audit judges by version alone, so conditions such as not running on Windows or not using next/og are not taken into account, and the warning remains until you update even if those conditions don't apply.

Apps that depend directly on Satori or @vercel/og need a separate check. When we ran npm audit on a setup with satori@0.33.4 as a dependency, this Satori advisory was not shown (we could not open its text from our environment, so it is unread). On npm, satori 0.33.5, which includes the fix commit, and @vercel/og 1.0.3, which depends on it, were published on September 22. If you depend on them directly, check the versions yourself.

Note that even with 15.5.27, the finding for the bundled postcss remained, and npm audit pointed to the major update 16.3.8. This article does not assess the impact of the postcss finding.

Common points of confusion when updating

  • Which version to upgrade to. The next/og fix starts at 16.3.6, and at the time of checking, latest on npm was 16.3.8 (published September 30). The 16.3.8 tag includes commits such as pinning DNS resolution when fetching external images and fixing a draft mode leak, but at the time of checking there were no corresponding advisories in the Advisory Database. Our editorial team proposes going all the way to 16.3.8 rather than stopping at 16.3.6, and verifying that everything works.
  • Don't work around it by switching to Edge. The Edge version is said to be unaffected, but the documentation marks runtime = 'edge' as not recommended, and Cache Components assume the Node.js runtime. The workaround, as stated in the advisory, is "don't pass external values," not changing the runtime.
  • Don't rely on the version shown for bundled components. Unpacking and comparing 16.3.5 and 16.3.6 shows that the image generation files in dist/compiled/@vercel/og changed, but the version of package.json in the same location is 0.11.1 in both. Judge whether the fix is present by the version of next itself (npm ls next).

On October 1, 2026, we directly read GHSA-vcvr-r3jv-pc5j, GHSA-p293-qw3h-jr36 and GHSA-2xp9-vwfh-vxw4 in the GitHub Advisory Database (commit 3113af4), the fix commits and tags in the Next.js and Satori repositories, and the source of the Next.js documentation (runtime, ImageResponse, Edge Runtime, cacheComponents). npm publication dates come from npm view, and we checked the diff between Next.js 16.3.5 and 16.3.6 by unpacking the packages. npm audit was run in our test environment (Linux, Node.js v22.22.0) against a minimal setup with only the dependencies installed; we did not build an app, reproduce the vulnerabilities or test behavior on Windows. The Satori advisory GHSA-wx4j-mvgx-mqwp and the Next.js release notes page could not be opened from our environment and are unread.

For update planning for sites and apps built with Next.js, and how to approach checks with your vendors, contact GleamHub.

Sources

Share this articleXFacebook
Kakeru Suzuki

Fascinated by the possibilities of technology, has had a deep interest in programming and digital art since student days

Turn this article's theme into your company's next step

Concrete steps forward for your organization.

We organize your desired architecture, legacy systems, and operational requirements to formulate your next steps toward execution.

  • Desired architecture
  • Integration with existing environments
  • Operational requirements
Consult on development & operations initiatives

You can consult with us from the initial conceptual stage. Details from this article will be carried over to the inquiry form.

Receive the latest articles by email