Next.js patches remote code execution flaw in next/og across v15 and v16 branches
On September 22, 2026, Next.js maintainer eps1lon released two versions simultaneously — v16.3.6 and v15.5.26 — both addressing a security issue in the next/og ImageResponse component. Version 16.3.6 explicitly references a Remote Code Execution vulnerability identified as GHSA-vcvr-r3jv-pc5j, while v15.5.26 describes the change as 'security hardening' without citing its own GHSA code. Both releases were published within one minute of each other, suggesting a coordinated response to the same underlying vulnerability across active branches. Neither release note mentions new features or general bug fixes, indicating these were purely security-focused updates. The parallel releases raise questions about the long-term support scope of the 15.x branch, though a single pair of releases is insufficient to draw conclusions about its full maintenance policy.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in