The Next.js team has disclosed a critical severity vulnerability in an upstream dependency that can lead to remote code execution when ImageResponse renders untrusted input. It is patched in 15.5.26 and 16.3.6. Applications that do not pass untrusted input into ImageResponse are not expected to be affected.
Security Update: Critical Next.js vulnerability in ImageResponse
calendar_today
September 22, 2026
domain
netlify