Next.js August 2026 Security Release: AVIF Image RCE, Windows RCE, and a Production Patch Plan
Next.js 16.3.3 and 15.5.24 patch two critical unauthenticated RCE issues: AVIF image optimization via sharp/libheif, and a Windows filesystem Server Action path. Here is who is affected, what Vercel already covers, and the self-hosted checklist.
By Mussawar Hayat
Two Critical RCEs, One Upgrade Window
On 25 August 2026, the Next.js team shipped v16.3.3 (Active LTS) and v15.5.24 (Maintenance LTS) after moving the advertised security window forward by a day. The reason: a second critical issue landed in an upstream image dependency while the first Windows-only RCE was already queued.
This is not a nice-to-have minor. Both issues are unauthenticated remote code execution. If you self-host Next.js — Docker, VPS, Windows Node, a company VM — treat this as a same-week patch. If you host only on Vercel, official guidance is that managed Image Optimization already applied protections and no customer redeploy is required for these two advisories. Confirm that claim against the current Vercel changelog before you skip the upgrade anyway.
What You Will Learn
- Official patched versions and the affected ranges
- What the AVIF / sharp / libheif issue means for next/image
- Who is exposed to CVE-2026-75604 on Windows
- Why Cache Components is not a substitute for upgrading
- A production checklist for Linux VPS, Docker, and mixed App + Pages apps
1. Official Versions
Patched releases named by the Next.js security post:
next@16.3.3for the 16.x Active LTS linenext@15.5.24for the 15.x Maintenance LTS line- Canary line:
16.4.0-canary.7and later for teams tracking canary
Publicly reported affected ranges include 13.4 through 15.5.23 and 16.0.x through 16.3.2, plus matching canaries. Pin the exact patched version in production. Do not stop at "latest 16" if your lockfile still resolves 16.3.2.
npm install next@16.3.3
# or
npm install next@15.5.24
npm ls nextRebuild the standalone output or container image after the bump. A running Node process that loaded the old node_modules/next is still the old binary.
2. Issue A — AVIF Image Optimization (Critical)
Tracked as unauthenticated RCE in the Image Optimization API when AVIF is processed. The root cause is not application code. It is a vulnerability in libheif, the library used by sharp, which Next.js uses to resize images.
If an attacker can get Next.js to optimize a crafted AVIF — typically by requesting the image optimizer with a reachable source — the decoder path can execute code. The official patch does not wait for an upstream libheif fix. It disables AVIF optimization in the patched Next.js releases until that upstream fix lands.
Production implications:
- Self-hosted apps that still advertise AVIF in
images.formatsshould dropimage/avifuntil Next.js re-enables it. - Do not point
remotePatternsat open hosts. An open remote image allow-list plus a public optimizer is how untrusted bytes reach sharp. - If you front Next.js with your own image CDN, confirm whether that CDN still decodes AVIF with a vulnerable libheif.
- Vercel stated it disabled AVIF on the managed optimizer when the issue was identified. Self-hosted Nginx + standalone Node does not get that for free.
WebP remains the safe default format for marketing sites. Users do not notice the missing AVIF if LCP images are already compressed WebP.
3. Issue B — Windows Filesystem RCE (CVE-2026-75604)
The second critical issue is CVE-2026-75604 (GHSA-p293-qw3h-jr36). Official impact statement: unauthenticated remote code execution on Windows-hosted Next.js servers when the app uses both the Pages Router and the App Router without Cache Components.
Linux and macOS are not affected by this second issue. There is no official workaround for Windows hosts other than upgrading.
Public analysis of the fix describes a path-separator gap: backslash is a directory delimiter on Windows and was not treated the same as forward slash during cache-path sanitization. That class of bug is enough to walk out of a cache directory and reach internal server files used in the Server Action trust path.
This guide does not include exploit steps. You do not need them to decide to patch. If your production Node process runs on Windows, assume exposure until 15.5.24 or 16.3.3 is running.
Cache Components being enabled is mentioned as a condition that changes the surface. It is not an approved mitigation. Enabling a caching flag is not a security program. Upgrade.
4. Who Must Move This Week
- Vercel-only, no self-hosted preview: platform protections cover these two issues. Still align local and CI to 16.3.3 so preview builds match production.
- Linux VPS / Docker / Coolify / Railway / Render: patch Next.js, drop AVIF from
images.formats, restrictremotePatterns, redeploy standalone. - Windows Server / Azure Windows: emergency patch. No workaround.
- Mixed App Router + leftover Pages API: higher priority. The Windows advisory explicitly calls out dual-router apps.
- Internal admin Next.js behind SSO: still patch. Unauthenticated means the Next.js process itself is the trust boundary, not your login page.
5. Production Checklist
- Bump
nextandeslint-config-nexttogether so lint plugins match the compiler. - Commit the lockfile. Confirm
npm ls nextprints only the patched version. - Set
images.formatsto["image/webp"]until AVIF is officially re-enabled. - Tighten
images.remotePatternsto first-party hosts. - Confirm
output: "standalone"images copy the new.next/standalonetree, not an old layer cache. - On Windows hosts, schedule the deploy as a security change, not a feature train.
- After deploy, hit a known
next/imageURL and confirm AVIF is no longer negotiated if you removed the format. - Re-run auth and Server Action smoke tests.
Keep treating every Server Action as a public endpoint. The July 2026 release already covered Server Action and middleware hardening. This August release does not replace that work. See the earlier guide on the July 2026 Server Actions patch and auth, validation, and DAL patterns.
6. Linux VPS + Nginx Notes
Most production work I ship runs Next.js standalone behind Nginx on Linux. That stack is outside the Windows RCE. It is not outside the AVIF optimizer issue.
Typical gaps:
- A Docker layer cache that reuses
node_modulesfrom last week images.formatsstill listing AVIF because a Lighthouse article recommended it in 2024remotePatternscopied from a tutorial with a wildcard hostname
Fix the image config in the same PR as the version bump. Then invalidate the Docker build cache for the deps stage. If you use multi-stage builds, the standalone copy step is where old binaries hide. Layout notes: Docker multi-stage builds for Next.js 16.
FAQ
Does hosting on Vercel mean I can ignore 16.3.3?
Vercel says applications on its platform are protected from these two August 2026 issues and do not require a customer redeploy. You should still upgrade local, preview, and any non-Vercel copy of the same repo so you are not developing against a vulnerable optimizer.
Are Linux servers safe from CVE-2026-75604?
The official advisory says Linux and macOS are not affected by the Windows filesystem RCE. They are still in scope for the AVIF optimizer issue if you self-host Image Optimization.
Is enabling Cache Components enough?
No. Cache Components changes part of the Windows surface. It is not an approved workaround. Upgrade to 16.3.3 or 15.5.24.
Should I keep serving AVIF?
Not from Next.js Image Optimization until the project re-enables it after an upstream libheif fix. Serve WebP. Revisit AVIF when the official release notes say the decoder path is safe again.
I only use the App Router. Am I out of scope for the Windows issue?
The official wording highlights apps that use both routers without Cache Components. If the process runs on Windows, patch. Do not parse the dual-router sentence as a reason to wait.
Summary
August 2026 is a two-bug release: a decoder RCE in the AVIF path, and a Windows path-sanitization RCE that can reach Server Action trust material. The correct response is a version pin, a lockfile commit, an image-format change, and a clean rebuild of standalone or container artifacts.
Key Takeaway
Patch to Next.js 16.3.3 or 15.5.24 this week. Turn off AVIF optimization. Do not use Cache Components or a Linux hostname as an excuse to skip the upgrade on every environment that still runs the old binary.
Need a self-hosted Next.js patch and rebuild?
I upgrade production App Router apps on VPS and Docker, including standalone output, Nginx, and image pipeline changes. Get in touch or review full-stack and DevOps services.
Related reading: July 2026 Server Actions security patch, Secure Server Actions in Next.js 16, and Docker multi-stage production builds.
Related guides
Ship a strict Content-Security-Policy, HSTS, Referrer-Policy, and Permissions-Policy on Next.js 16 App Router without breaking Server Actions, images, or analytics. Includes nonce patterns, report-only rollout, and Nginx notes for VPS hosts.
Secure Server Actions in Next.js 16: Auth, Validation & Data Access LayerEvery Server Action is a public POST endpoint. Production pattern for Next.js 16: validate inputs with Zod, authenticate from session, authorize ownership, keep a thin action layer on a server-only Data Access Layer, constrain return values, and revalidate safely.
Next.js July 2026 Security Patch: Server Actions & Middleware Hardening GuideJuly 2026 Next.js security release: what changed, how to upgrade, Server Action allowedOrigins, middleware pitfalls, and a production App Router checklist after CVE-class fixes.
