Blog

Insights on software development, security, and technology from our team.

Showing posts taggednextjs

A Next.js OG-image bug can run code on your server. Patch to 16.3.6.

Vercel shipped an out-of-band Next.js update on September 22 to fix CVE-2026-94545, a critical remote code execution bug in the Node.js `ImageResponse` from `next/og`, scored CVSS 9.5. It only bites apps that feed visitor-controlled values into dynamic Open Graph images, but that describes most share-card setups. Here is who is exposed, why patching the framework alone may not be enough, and what to check today.

React Compiler goes Rust, and Next.js 16.3 can already use it

The React team rewrote the React Compiler in Rust, and Vercel wired it into Turbopack. Next.js 16.3 reports 20 to 50% faster route compilation on the native path. We break down whether the experimental flag is worth flipping, and how to test it without risking production.

Next.js just patched 13 security advisories. Self-hosted teams have the most work.

Vercel shipped a coordinated security release on May 7: 13 Next.js and React Server Components advisories covering DoS, SSRF, cache poisoning, and middleware bypasses in App Router. Self-hosted teams running Node are hit hardest. The deeper takeaway: middleware was never an authorization boundary.