BREAKING: Next.js image optimizer SSRF and cache poisons in September 2026 release
How to fix CVE-2026-94483: upgrade next to 15.5.27 or 16.3.8
Contents
Next.js shipped a same-day September 2026 security release. If your app fetches remote images through the built-in Image Optimization path with images.remotePatterns set, an attacker-controlled allow-listed URL can make the server request private IP ranges. That is CVE-2026-94483 (High). The same train also hardens several Medium cache-poison and Draft Mode leak bugs, plus a Low next dev MCP disclosure.
Fixed builds: [email protected] (15.5 Maintenance LTS) and [email protected] (16.3 Active LTS). One upgrade covers the cluster. Do not wait for a separate post per CVE on this train.
npm install [email protected] # 15.5
npm install [email protected] # 16.3
Operator evidence for the lead issue lives on the HOL Guard pack for CVE-2026-94483. Primary vendor write-up: September 2026 Security Release.
Who is not in scope
- Image SSRF (CVE-2026-94483): apps with no
images.remotePatternsconfigured are not affected. - Pages Router SSG/ISR cache poison (CVE-2026-94543): Vercel-hosted apps are not affected. Self-hosted Pages Router with SSG/ISR is.
- Metadata image
dynamicParamsbypass (CVE-2026-94485): Turbopack builds are not affected. Webpack App Router builds are. - Dev MCP disclosure (CVE-2026-94486): production deployments do not serve the endpoint. Only
next dev. - This is not a remote code execution drop like the earlier next/og ImageResponse issue. Do not confuse it with GHSA-vcvr-r3jv-pc5j.
Concrete operator check
npx next --version
# expect 15.5.27+ on the 15.5 line, or 16.3.8+ on the 16.3 line
# Image SSRF scope gate (next.config.*):
# if images.remotePatterns is absent / empty -> CVE-2026-94483 out of scope
# if remotePatterns allow attacker-influenced hosts -> treat as in scope until patched
grep -R "remotePatterns" next.config.* 2>/dev/null || true
grep -R "use cache\|experimental.useCache\|cacheComponents" app src pages 2>/dev/null | head
If you self-host Pages Router with SSG/ISR, or use a root-level catch-all next to static/ISR routes, assume the Medium cache-poison IDs apply until you are on the fixed builds. If Cache Components / experimental.useCache is on and you serve Draft Mode previews, treat CVE-2026-94544 and GHSA-h694-7cp9-m8p3 as in scope.
What broke
High: Image Optimization SSRF (CVE-2026-94483 / GHSA-cjq9-62q9-8jv4)
When remote image patterns are configured, an attacker-controlled allow-listed remote URL can drive Server-Side Request Forgery during Image Optimization, including toward private IP ranges. No remotePatterns means you skip this one. With remotePatterns, the blast radius is "your Next process will fetch what an attacker can steer inside the allow list," which is how internal metadata services and RFC1918 hosts get probed.
Medium: Pages Router SSG/ISR cache poison, self-hosted (CVE-2026-94543 / GHSA-4jqv-mc3x-m676)
Self-hosted apps using the Pages Router with SSG or ISR can have a page cache entry replaced with content from a different route. Every visitor then sees the wrong page until revalidation. Vercel is not affected.
Medium: catch-all + shared SSG/ISR cache poison (CVE-2026-94484 / GHSA-mcj8-r9mp-w47p)
A root-level catch-all page combined with statically generated or ISR routes can have the shared response cache poisoned by a single unauthenticated crafted request. Cross-user content substitution and a sticky denial of service until the entry is cleared.
Medium: App Router metadata images ignore dynamicParams (CVE-2026-94485 / GHSA-f87g-xv8r-7p7x)
Webpack App Router builds: metadata image routes such as opengraph-image / twitter-image ignore dynamicParams. Attackers can request metadata image URLs for dynamic segments you deliberately excluded from generateStaticParams(). Turbopack builds are not affected.
Medium: nested use cache root-param leak (GHSA-h694-7cp9-m8p3)
With Cache Components enabled, a use cache function that calls another use cache function reading a root param can key incorrectly. Content for one root param value can be served for another. The leaked values are not attacker-chosen; they are cross-tenant confusion inside your own param space.
Medium: Draft Mode into regular / persisted pages (CVE-2026-94544 / GHSA-3w37-wq28-93x7)
Pending use cache fills are shared across requests for the same key without distinguishing Draft Mode from regular traffic. A regular request that overlaps an editor's Draft Mode fill can receive unpublished content with no auth. If that request prerenders, draft content can persist into the generated page for later visitors until revalidation. Sites need Cache Components (or experimental.useCache) plus Draft Mode previews whose cached functions return draft-dependent content.
Low: next dev MCP endpoint disclosure (CVE-2026-94486 / GHSA-39w2-rjm5-chcv)
The development server exposes a Model Context Protocol endpoint that does not verify which website a request originates from. A malicious site the developer visits can read sensitive dev data: project path on disk, source snippets from error reports, route inventory, and development logs. Production does not serve this endpoint.
What this is not
This is not unauthenticated RCE on production Next.js, not a wormable internet takeover, and not the earlier next/og ImageResponse RCE. The High issue is SSRF gated on remotePatterns. The Medium issues are cache confusion, Draft Mode bleed, and metadata image disclosure under specific router/bundler setups. The Low issue is local-dev only.
How to fix
npm install [email protected] # Maintenance LTS 15.5
npm install [email protected] # Active LTS 16.3
Redeploy after the bump. If you cannot upgrade immediately:
- For CVE-2026-94483: tighten or remove
images.remotePatternsso attacker-influenced hosts cannot sit on the allow list; prefer a locked CDN/host set. - For cache-poison IDs: prefer Vercel hosting where the vendor says you are out of scope for CVE-2026-94543, or isolate self-hosted catch-all + SSG/ISR layouts until patched.
- For Draft Mode / Cache Components leaks: keep Draft Mode off public edges, and avoid overlapping anonymous traffic with editor Draft Mode fills on shared cache keys.
- For CVE-2026-94486: do not expose
next devto untrusted browsers or share a browser profile that hits hostile sites while the dev server is up.
References
- Next.js September 2026 Security Release (Wed Sep 30, 2026)
- CVE-2026-94483 / GHSA-cjq9-62q9-8jv4 (High SSRF)
- CVE-2026-94543 / GHSA-4jqv-mc3x-m676
- CVE-2026-94484 / GHSA-mcj8-r9mp-w47p
- CVE-2026-94485 / GHSA-f87g-xv8r-7p7x
- GHSA-h694-7cp9-m8p3
- CVE-2026-94544 / GHSA-3w37-wq28-93x7
- CVE-2026-94486 / GHSA-39w2-rjm5-chcv
Continue reading
All posts
BREAKING: CVE-2026-94545 Next.js next/og ImageResponse RCE (GHSA-vcvr-r3jv-pc5j)
How to fix CVE-2026-94545: upgrade next to 16.3.6 (15.5.26 hardening if you stay on 15.x)

BREAKING: CVE-2026-86259 lets unauth OpenMAIC callers pull cloud credentials via SSRF
How to fix CVE-2026-86259: upgrade OpenMAIC to 1.0.1

BREAKING: Cisco SD-WAN Manager admin API open without a login (CVE-2026-76504)
How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1
