Skip to content
01.10.2026Web platform · 5 min read

Next.js 16.3.8 security: self-hosted vs Vercel.

Next.js 16.3.8 fixes seven bugs, four of them cache leaks that hit self-hosted storefronts harder than Vercel, while a critical fix is still pending upstream.

The Next.js 16.3.8 security release is mostly a caching release. Four of its seven fixes are cache bugs that can serve one visitor's page to another, and two of those four only bite when you run the cache yourself. If your headless storefront is self-hosted rather than on Vercel, this is the patch to apply this week, and it will not be the last one this quarter.

What Next.js shipped on September 30, 2026

Next.js 16.3.8 (Active LTS) and 15.5.27 (Maintenance LTS) fix seven vulnerabilities: one high, five medium and one low, according to the September 2026 security release post. The high one is a server-side request forgery in Image Optimization, CVE-2026-94483, scored 8.3 under CVSS 4. It only matters if images.remotePatterns allows a host whose DNS you do not fully trust, because an attacker who controls that DNS can point the optimizer at private IP ranges.

The medium tier is where the volume is. CVE-2026-94543 lets a self-hosted Pages Router site with SSG or ISR pages store one route's content under another route's cache entry, and every visitor gets the wrong page until revalidation. CVE-2026-94484 does something similar to sites that combine a root-level catch-all page with static or ISR routes, and a single unauthenticated request is enough to poison the shared cache. Both affect the 15.x and 16.x lines. Two more bugs are specific to Cache Components in 16.3.0: a nested 'use cache' function can drop a root param from its cache key, and a pending cache fill can leak Draft Mode content to an ordinary visitor and even bake it into a prerendered page. The remaining medium, CVE-2026-94485, lets anyone fetch opengraph-image routes for params you excluded from generateStaticParams(), on webpack builds only. The low one, CVE-2026-94486, is an MCP endpoint on next dev that any website the developer visits can read.

The release is also short two fixes. The advance notice promised nine vulnerabilities, then was updated on release day: one critical and one high are waiting on upstream coordination and will ship in a later version.

Self-hosted vs Vercel: who carries the cache risk

Self-hosted Next.js carries more of this release's risk than Vercel-hosted Next.js, because on a self-hosted stack the cache is part of your infrastructure, not the vendor's. The advisory for CVE-2026-94543 says plainly that apps on Vercel are not affected. Vercel's managed cache sits outside the code path that breaks, while the default self-hosted cache and custom cache handlers sit inside it.

Self-hosting has real reasons behind it in Asia. Teams put the storefront in Singapore or Jakarta cloud regions for latency, keep data in country for regulated categories, or sit Next.js behind the same CDN that fronts a Magento or Shopify backend. All valid. The cost is that a cache-key bug in the framework becomes a cache-key bug in your CDN too. A poisoned entry with public cache headers can be copied to every edge node, and purging the origin does not purge the edge. The GHSA for the nested 'use cache' leak notes that shared cache headers let downstream caches spread the wrong content further, and it lists no workaround at all.

For commerce, the content that leaks is the expensive kind. Root params are what multi-region storefronts commonly use for locale and market. A cache key that ignores them can show Indonesian rupiah prices on the Singapore store, or a members-only collection on the public one. The Draft Mode bug is worse for brands that stage launches in a headless CMS: an unannounced drop can surface on the live site because an editor previewed it at the same moment a shopper loaded the page.

What we would actually change this week

Upgrade to 16.3.8 or 15.5.27 first, then audit the three settings that decide your exposure, because the patch fixes the framework but not a CDN that already cached bad content. On our headless commerce builds the order is:

  1. Patch, redeploy, then purge the CDN and the Next.js data cache together. A clean origin behind a dirty edge is still a dirty site.
  2. Review images.remotePatterns. Wildcards on subdomains of a DAM, a marketplace or a supplier host are the SSRF surface. Pin exact hostnames where you can.
  3. List every route under a root catch-all and every route using ISR. That inventory tells you whether CVE-2026-94484 applied to you and which pages to recheck by hand.
  4. If you run Cache Components with Draft Mode, keep draft-dependent reads out of shared 'use cache' functions. Read draft state at the page boundary and pass it down, so the cached layer never sees it.

The dev server bug deserves its own line in onboarding docs. A local next dev process now exposes an MCP endpoint that AI coding agents talk to, and until this patch a malicious page in another tab could read your route list, file paths and logs. As agent-assisted development becomes normal on our AI-native work, the dev machine is part of the attack surface. Patch local toolchains too, not only production.

Why the two pending fixes change your patch plan

Two withheld fixes mean a second Next.js upgrade is coming, likely at short notice, so treat 16.3.8 as a rehearsal rather than the end of the cycle. One of the pending issues is rated critical. When its advisory lands, the details become public at the same moment as the patch, and the gap between disclosure and exploitation on popular frameworks is measured in days.

This is the fourth Next.js security release since July, after the next/og remote code execution patch on September 22. A storefront that needs a sprint to bump a minor version is a liability at that cadence. The fix is boring: a lockfile bot that opens the upgrade pull request within hours, a smoke test suite that covers checkout, search and the cached PDP and PLP routes, and a documented purge step. If your e-commerce stack cannot go from advisory to production in under a day, that is the gap to close before the critical fix ships.

Where to dig deeper

Same topics, adjacent entries
J–04108.2026 · 5 min

Hyva Checkout compatibility: official vs shim

J–04208.2026 · 6 min

Next.js 16.3.3: AVIF RCE vs Windows RCE

J–06109.2026 · 5 min

Shopify packed dimensions vs weight-only rates

J–00105.2026 · 2 min

We're starting a journal

Want this done right on your store?

We engineer premium e-commerce end-to-end, Magento Hyvä, Shopify Plus, mobile and automation. A two-week store audit turns ideas like the one above into real numbers and a prioritised roadmap for your store.