v16.3.8
Summary
This release contains security fixes for the following advisories: High: Server-Side Request Forgery in Image Optimization Medium: Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass Cache poisoning of SSG and ISR pages in self-hosted Next.js applications Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitution and persistent denial of service Pending use cache fill can leak Draft Mode content into regular responses and persisted pages Cache leak across root param values in nested 'use cache' functions Low: Information disclosure in the Next.js development server's Model Context Protocol endpoint
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.