# Next.js vulnerabilities in 2026, the AVIF RCE and the version to run (/en/blog/nextjs-vulnerabilities-2026)



On 25 August 2026 Vercel shipped Next.js 16.3.3 and 15.5.24 to fix two critical unauthenticated remote code execution (RCE) flaws: one in the Image Optimization API when it handles AVIF files, and one on Windows-hosted servers. Five weeks later, on 30 September, 16.3.8 and 15.5.27 fixed seven more advisories. If you run Next.js yourself, the version to be on today is **16.3.8** or **15.5.27**, not the August release.

This post covers the two RCEs, who is exposed, the version to run per release line, and every Next.js security release of 2026, with React2Shell from December 2025 at the start because it still drives most "is my Next.js version vulnerable" searches.

## Next.js vulnerability 2026, the AVIF image RCE [#nextjs-vulnerability-2026-the-avif-image-rce]

The advisory is [GHSA-2xp9-vwfh-vxw4](https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4), titled "Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used". It is rated Critical, CVSS 9.5 (CVSS 4.0), and had no CVE id at the time of writing.

The flaw is not in Next.js code. Next.js optimizes images with [sharp](https://sharp.pixelplumbing.com/), sharp decodes AVIF through the [libheif](https://github.com/strukturag/libheif) library, and libheif has a memory corruption bug tracked upstream as [GHSA-g89c-p67h-r497](https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497). When Next.js optimizes an attacker-controlled AVIF image, that bug can lead to code execution on the server.

* **Affected:** Next.js 10.0.0 up to 15.5.23, and 16.x before 16.3.3.
* **Fixed:** 15.5.24 and 16.3.3. The fix disables AVIF optimization until a patched libheif reaches sharp: AVIF images are served as-is, not resized.
* **Exposed:** self-hosted applications that enable AVIF. Next.js only optimizes to AVIF when `image/avif` is in `images.formats` in `next.config.js`; the default is `['image/webp']`. Applications hosted on Vercel are protected and need no action, according to Vercel.

The release also fixed [CVE-2026-75604](https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36), a second critical RCE (CVSS 9.0). It is a path traversal in the incremental cache that only works on servers running on a Windows filesystem, in applications that use both the Pages Router and the App Router without Cache Components. It affects 13.4 and later before 15.5.24, and 16.0 before 16.3.3. Linux and macOS are not affected, and Vercel lists no workaround. A public proof of concept has been published on GitHub.

## Which Next.js version to run now [#which-nextjs-version-to-run-now]

Upgrade to the September release, which includes the August fixes and seven more:

```bash
npm install next@16.3.8   # Active LTS
npm install next@15.5.27  # Maintenance LTS
```

| Release line   | Minimum version for the AVIF and Windows RCEs | Version to run today      |
| -------------- | --------------------------------------------- | ------------------------- |
| 16.x           | 16.3.3                                        | 16.3.8                    |
| 15.x           | 15.5.24                                       | 15.5.27                   |
| 14.x and older | No patched release                            | Move to 15.5.27 or 16.3.8 |

Vercel publishes security fixes for the Active LTS (16.3) and Maintenance LTS (15.5) lines. If you are on 15.0 to 15.4 or 16.0 to 16.2, upgrade within your major version to the patched release above. The May 2026 release notes state that every 13.x and 14.x version is affected by that release's advisories.

## Am I affected? [#am-i-affected]

Check the version first, then the conditions. A version in the affected range does not prove an application is exploitable; a version outside it rules the advisory out.

For the AVIF RCE (GHSA-2xp9-vwfh-vxw4), you are exposed only if all of these hold:

* You self-host Next.js (your own server, container, or a host other than Vercel).
* `images.formats` in `next.config.js` contains `image/avif`.
* Your version is 10.0.0 to 15.5.23, or a 16.x release before 16.3.3.

For CVE-2026-75604, you are exposed only if all of these hold:

* The Next.js server runs on Windows.
* The application uses both the Pages Router and the App Router, without Cache Components.
* Your version is 13.4 or later and before 15.5.24, or 16.x before 16.3.3.

If you cannot upgrade today, remove `image/avif` from `images.formats` so AVIF optimization stops. That closes the AVIF path only. There is no workaround for the Windows flaw.

```js
// next.config.js
module.exports = {
  images: {
    formats: ['image/webp'], // was ['image/avif', 'image/webp']
  },
}
```

## Every Next.js security release of 2026 [#every-nextjs-security-release-of-2026]

Next.js moved to preannounced security releases in July 2026, so fixes now land in batches on dated releases. The fixed versions below are the ones Vercel published for each batch.

| Date        | Advisories                                                                                                                                        | Highest severity    | Impact                                                                                                                                                                                 | Fixed in                                               |
| ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------ |
| 3 Dec 2025  | [CVE-2025-66478](https://nextjs.org/blog/CVE-2025-66478) (React [CVE-2025-55182](https://www.cve.org/CVERecord?id=CVE-2025-55182), "React2Shell") | Critical, CVSS 10.0 | Unauthenticated RCE through the React Server Components protocol, App Router only. Exploited in the wild, added to the CISA Known Exploited Vulnerabilities catalog on 5 December 2025 | 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7 |
| 16 Mar 2026 | [CVE-2026-27980](https://github.com/advisories/GHSA-3x4c-7xq6-9pq8)                                                                               | Moderate, CVSS 6.9  | The `/_next/image` disk cache had no size limit, so requests for many image variants could fill the disk (denial of service), mainly on self-hosted apps                               | 15.5.14, 16.1.7                                        |
| 7 May 2026  | [13 advisories](https://vercel.com/changelog/next-js-may-2026-security-release), including React CVE-2026-23870                                   | High                | Authorization and middleware bypasses, SSRF through WebSocket upgrades, denial of service in React Server Components, cache poisoning, XSS                                             | 15.5.18, 16.2.6                                        |
| 20 Jul 2026 | [9 advisories](https://nextjs.org/blog/july-2026-security-release), including CVE-2026-64641, CVE-2026-64642, CVE-2026-64645, CVE-2026-64649      | High                | Server Actions denial of service, middleware bypass with Turbopack and a single locale, SSRF through rewrites and Server Actions                                                       | 15.5.21, 16.2.11                                       |
| 25 Aug 2026 | [GHSA-2xp9-vwfh-vxw4 and CVE-2026-75604](https://nextjs.org/blog/august-2026-security-release)                                                    | Critical            | Unauthenticated RCE through AVIF optimization, and on Windows-hosted servers                                                                                                           | 15.5.24, 16.3.3                                        |
| 30 Sep 2026 | [7 advisories](https://nextjs.org/blog/september-2026-security-release), including CVE-2026-94483                                                 | High                | SSRF in Image Optimization when `images.remotePatterns` is set, SSG and ISR cache poisoning, information disclosure                                                                    | 15.5.27, 16.3.8                                        |

Two patterns stand out. Three of the 2026 batches (March, August and September) touch the Image Optimization API (`/_next/image`), which is the part of Next.js that processes untrusted input by design. And the self-hosted path carries most of the exposure: several advisories state that Vercel deployments are not affected.

## How to check which Next.js version a site runs [#how-to-check-which-nextjs-version-a-site-runs]

On your own project, the answer is in `package.json` and the lockfile: `npm ls next` prints the installed version.

From the outside, paste the URL into the free [Technology Checker](/tools/tech-checker). It lists the technologies the page uses, including Next.js when it can read it, with the version, whether that version is outdated or at end of life, and the known CVEs affecting it, each with the version that fixes it. The checker reads the page, not your server configuration: it cannot see `images.formats`, your hosting platform, or which router you use. Check the version there, then check the conditions above.

The same check covers the rest of the page, since the CVEs most sites carry come from libraries loaded next to the framework. For the method behind finding those, read [How to detect vulnerable JavaScript libraries on a live website](/en/blog/detect-vulnerable-javascript-libraries); for the manual and tool-based ways to read a site's stack, [What technology is this website using, and is any of it outdated](/en/blog/what-technology-is-this-website-using).

## Get told when the next advisory lands [#get-told-when-the-next-advisory-lands]

A one-off check answers for one page on one day, and Next.js has shipped five security batches in 2026 so far. CentralCSP inventories the scripts your visitors' browsers run on every page, identifies the library and version behind each one, and alerts you when a new CVE affects a version you serve. The inventory is described in [Technologies](/en/docs/platform/features/technologies), and the [supply-chain feature page](/platform/supply-chain) has the tour.

Patching the framework is half the work on a Next.js site. The other half is limiting what an injected script could do if one got through, which a strict Content Security Policy (CSP) handles: see [How to set up a CSP nonce in Next.js](/en/blog/csp-nonce-nextjs) and [Google Tag Manager under a strict CSP in Next.js](/en/blog/gtm-csp-nextjs). [Start free with CentralCSP](/register) to see the versions your pages serve.

## FAQ [#faq]

### Is my Next.js version vulnerable? [#is-my-nextjs-version-vulnerable]

If you run a version older than 16.3.8 or 15.5.27, at least one 2026 advisory applies to it. Whether it is exploitable depends on the advisory's conditions: the AVIF RCE needs self-hosting and `image/avif` in `images.formats`, and CVE-2026-75604 needs a Windows server. Upgrading to 16.3.8 or 15.5.27 covers every advisory listed in this post.

### Does the AVIF vulnerability affect apps hosted on Vercel? [#does-the-avif-vulnerability-affect-apps-hosted-on-vercel]

No. Vercel states that applications hosted on its platform are protected and need no upgrade, configuration change, or redeploy. Self-hosted applications that enable AVIF in `images.formats` are the ones exposed.

### Does GHSA-2xp9-vwfh-vxw4 have a CVE id? [#does-ghsa-2xp9-vwfh-vxw4-have-a-cve-id]

Not at the time of writing. The Next.js advisory lists no CVE, and the root cause is tracked upstream in libheif as GHSA-g89c-p67h-r497. Search for the GHSA id when you look up fixes or scanner findings.

### What was React2Shell? [#what-was-react2shell]

React2Shell is the name given to CVE-2025-55182, a CVSS 10.0 flaw in the React Server Components protocol disclosed on 3 December 2025, tracked in Next.js as CVE-2025-66478. It allowed unauthenticated RCE in App Router applications on Next.js 15.x and 16.x, was exploited in the wild within days, and is fixed in the versions listed in the timeline. Vercel's `npx fix-react2shell-next` tool updates affected projects.

### Is Next.js 14 still supported? [#is-nextjs-14-still-supported]

Vercel publishes security fixes for the 16.3 and 15.5 lines. The May 2026 release notes state that all 13.x and 14.x versions are affected by that release's advisories, so a 14.x application should move to 15.5.27 or 16.3.8.

## Related [#related]

* [How to detect vulnerable JavaScript libraries on a live website](/en/blog/detect-vulnerable-javascript-libraries)
* [What technology is this website using, and is any of it outdated](/en/blog/what-technology-is-this-website-using)
* [How to set up a CSP nonce in Next.js](/en/blog/csp-nonce-nextjs)
* [Google Tag Manager under a strict CSP in Next.js](/en/blog/gtm-csp-nextjs)

## Sources [#sources]

* [Next.js, August 2026 Security Release](https://nextjs.org/blog/august-2026-security-release)
* [GitHub, GHSA-2xp9-vwfh-vxw4, RCE in Image Optimization API with AVIF](https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4)
* [GitHub, GHSA-p293-qw3h-jr36, CVE-2026-75604](https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36)
* [libheif, GHSA-g89c-p67h-r497](https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497)
* [Vercel changelog, Next.js August 2026 security release](https://vercel.com/changelog/nextjs-august-2026-security-release)
* [Next.js, September 2026 Security Release](https://nextjs.org/blog/september-2026-security-release)
* [Next.js, July 2026 Security Release](https://nextjs.org/blog/july-2026-security-release)
* [Vercel changelog, Next.js May 2026 security release](https://vercel.com/changelog/next-js-may-2026-security-release)
* [GitHub Advisory Database, CVE-2026-27980](https://github.com/advisories/GHSA-3x4c-7xq6-9pq8)
* [Next.js, Security Advisory CVE-2025-66478](https://nextjs.org/blog/CVE-2025-66478)
* [Rapid7, React2Shell CVE-2025-55182](https://www.rapid7.com/blog/post/etr-react2shell-cve-2025-55182-critical-unauthenticated-rce-affecting-react-server-components/)
* [Next.js docs, Image component formats](https://nextjs.org/docs/app/api-reference/components/image)
* [The Hacker News, Next.js patches critical AVIF and Windows flaws](https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html)
