Next.js Critical Security Release: What Defenders Should Do
What happened
Vercel released patches for two critical Next.js issues that can allow unauthenticated remote code execution in specific deployment conditions. One issue affects Windows-hosted servers through a path traversal class, while another is tied to AVIF image optimization through an upstream parsing dependency.
Who is affected
Teams running self-hosted Next.js applications are most exposed, particularly Windows-hosted deployments and applications that explicitly enable AVIF optimization.
Why it matters
Next.js is widely used in production web stacks. Critical vulnerabilities in framework and dependency processing paths can become high-priority patching events for both application security and platform operations teams.
Technical details
- CVE-2026-75604: critical Windows filesystem path traversal issue (CVSS 9.0)
- AVIF optimization chain: critical upstream libheif overflow advisory (GHSA-g89c-p67h-r497), reflected in Next.js security guidance (GHSA-2xp9-vwfh-vxw4)
- Affected ranges include pre-patch 15.5.x and 16.3.x branches
- Fixed versions: Next.js 15.5.24 and 16.3.3
- Exploitation status at publication: no confirmed in-the-wild exploitation reported for these August issues
Recommended actions
- Upgrade immediately to supported patched versions.
- Prioritize Windows-hosted instances and internet-facing applications.
- Review whether image/avif optimization is enabled and assess exposure.
- Validate WAF, logging, and anomaly monitoring for image-processing and traversal probes.
- Track Vercel and upstream advisories for further hardening updates.
Sources
- https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html
- https://nextjs.org/blog/august-2026-security-release
- https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36
