Skip to content
chornous.dev

Type two or more letters. Esc closes.

Index of sheets
Theme

Sheet 03 · Writing

All notes

The next/og advisory, and another Next.js patch on September 30

A critical advisory on September 22, 2026 covers Next.js 16.2.0 to 16.3.5 through the Node.js ImageResponse in next/og, and a scheduled release on September 30 will fix nine more issues. Triage steps for sites that render OG images.

Pl. 96 · section drawing generated from the slug “nextjs-og-image-rce-september-2026”

On September 22, 2026 the Next.js team shipped an out-of-band security update for a critical issue in next/og, the module many Next.js sites use to draw their social cards. A day later they announced a scheduled release for September 30 with nine more fixes. If your site generates OG images, put both dates in your plan.

The advisory

From the Next.js and Satori advisories
FieldDetail
AdvisoryGHSA-vcvr-r3jv-pc5j, CVE-2026-94545
SeverityCritical, CVSS 9.5: remote code execution
AffectedNext.js >=16.2.0 <16.3.6
Fixed in16.3.6 (Active LTS); 15.5.26 adds hardening only
UpstreamGHSA-wx4j-mvgx-mqwp in Satori, Moderate 5.3, fixed in 0.33.5
Not affectedthe Edge ImageResponse, Next.js 15.x, and apps that pass no attacker-controlled values

Satori turns the JSX you pass to ImageResponse into SVG, and it didn't escape certain values before writing them out. The advisory states the precondition: the attack needs "attacker-controlled values" in the SVG's content, attributes or styles, rendered by the Node.js implementation. An attacker could chain that escaping gap with other upstream dependencies to reach remote code execution.

Triage in five steps

  1. Step 1

    Check your version: npm ls next. Anything from 16.2.0 up to 16.3.5 is in range.
  2. Step 2

    Find the image routes: search for ImageResponse and next/og, and for opengraph-image and twitter-image files.
  3. Step 3

    Check the runtime. Only the Node.js implementation is affected; routes on the Edge runtime are not.
  4. Step 4

    Check the inputs. Does any request value, such as a query string, a path segment or a user's profile name, reach the JSX?
  5. Step 5

    Upgrade to 16.3.6 and redeploy.

If you can't upgrade today, the advisory's workaround is to stop passing attacker-controlled values into the SVG. Accept an id and look the text up on the server instead of accepting the text itself:

import { ImageResponse } from "next/og";

export async function GET(
  _request: Request,
  { params }: { params: Promise<{ slug: string }> },
): Promise<Response> {
  // Before: const title = new URL(_request.url).searchParams.get("title");
  const { slug } = await params;
  const post = await getPostBySlug(slug);
  if (!post) return new Response("Not found", { status: 404 });
  return new ImageResponse(<Card title={post.title} />, { width: 1200, height: 630 });
}

September 30

The scheduled release will address nine vulnerabilities:

critical
1
high
2
medium
5
low
1

The planned versions are 16.3.7 and 15.5.27, with full advisories published at release time. Taking 16.3.6 now doesn't spare you the second upgrade. The September 22 details are already public, and the September 30 ones aren't yet, so patch now and block an hour on the 30th for 16.3.7.

Counting September 30, that's three Next.js security releases since August 25, and December 2025's React Server Components advisories came in two rounds as well. I keep a patch lane that can ship a dependency bump the same day.

Sources

Volodymyr Chornous