next

next breaking-changes badge

next (latest known version: 16.3.0) has 1314 known breaking changes on record, each backed by a source URL.

Actively maintainedLatest known version: 16.3.0npm ↗

Security advisories

GHSA-25mp-g6fv-mqxxHIGH>=12.0.0 <12.0.5 || >=0.9.9 <11.1.3

Unexpected server crash in Next.js.

source ↗

GHSA-267c-6grr-h53fHIGH>=15.2.0 <15.5.16 || >=16.0.0 <16.2.5

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes

source ↗

GHSA-26hh-7cqf-hhc6HIGH>=15.2.0 <15.5.18 || >=16.0.0 <16.2.6

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up

source ↗

GHSA-36qx-fr4f-26g5HIGH>=12.2.0 <15.5.16 || >=16.0.0 <16.2.5

Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n

source ↗

GHSA-3f5c-4qxj-vmpfHIGH>=1.0.0 <2.4.1

Next.js Directory Traversal Vulnerability

source ↗

GHSA-3g8h-86w9-wvmqLOW>=12.2.0 <15.5.16 || >=16.0.0 <16.2.5

Next.js's Middleware / Proxy redirects can be cache-poisoned

source ↗

GHSA-3h52-269p-cp9rLOW>=15.0.0 <15.2.2 || >=13.0 <14.2.30

Information exposure in Next.js dev server due to lack of origin verification

source ↗

GHSA-3x4c-7xq6-9pq8MODERATE>=16.0.0-beta.0 <16.1.7 || >=10.0.0 <15.5.14

Next.js: Unbounded next/image disk cache growth can exhaust storage

source ↗

GHSA-4342-x723-ch2fMODERATE>=0.9.9 <14.2.32 || >=15.0.0-canary.0 <15.4.7

Next.js Improper Middleware Redirect Handling Leads to SSRF

source ↗

GHSA-4633-3j49-mh5qMODERATE>=13.0.0 <15.5.21 || >=16.0.0 <16.2.11

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

source ↗

GHSA-492v-c6pp-mqqvHIGH>=15.4.0 <15.5.16 || >=16.0.0 <16.2.5

Next.js has a Middleware / Proxy bypass through dynamic route parameter injection

source ↗

GHSA-4c39-4ccg-62r3MODERATE>=13.0.0 <15.5.21 || >=16.0.0 <16.2.11

Next.js: Unbounded Server Action payload in Edge runtime

source ↗

GHSA-5j59-xgg2-r9c4HIGH>=13.3.1-canary.0 <14.2.35 || >=15.0.6 <15.0.7 || >=15.1.10 <15.1.11 || >=15.2.7 <15.2.8 || >=15.3.7 <15.3.8 || >=15.4.9 <15.4.10 || >=15.5.8 <15.5.9 || >=15.6.0-canary.59 <15.6.0-canary.60 || >=16.0.9 <16.0.10 || >=16.1.0-canary.17 <16.1.0-canary.19

Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

source ↗

GHSA-5vj8-3v2h-h38vHIGH>=0.9.9 <5.1.0

Remote Code Execution in next

source ↗

GHSA-67rr-84xm-4c7rHIGH>=15.0.4-canary.51 <15.1.8

Next.JS vulnerability can lead to DoS via cache poisoning

source ↗

GHSA-68g3-v927-f742MODERATE>=13.0.0 <15.5.21 || >=16.0.0 <16.2.11

Next.js: Cache confusion of response bodies for requests with bodies

source ↗

GHSA-6gpp-xcg3-4w24HIGH>=16.0.0 <16.2.11

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

source ↗

GHSA-77r5-gw3j-2mpfHIGH>=13.4.0 <13.5.1

Next.js Vulnerable to HTTP Request Smuggling

source ↗

GHSA-7gfc-8cq8-jh5fHIGH>=9.5.5 <14.2.15

Next.js authorization bypass vulnerability

source ↗

GHSA-7m27-7ghc-44w9MODERATE>=13.0.0 <13.5.8 || >=14.0.0 <14.2.21 || >=15.0.0 <15.1.2

Next.js Allows a Denial of Service (DoS) with Server Actions

source ↗

GHSA-89xv-2m56-2m9xHIGH>=14.1.1 <15.5.21 || >=16.0.0 <16.2.11

Next.js: Server-Side Request Forgery in Server Actions on custom servers

source ↗

GHSA-8h8q-6873-q5fjHIGH>=13.0.0 <15.5.16 || >=16.0.0 <16.2.5

Next.js Vulnerable to Denial of Service with Server Components

source ↗

GHSA-955p-x3mx-jcvpMODERATE>=13.0.0 <15.5.21 || >=16.0.0 <16.2.11

Next.js: Unauthenticated disclosure of internal Server Function endpoints

source ↗

GHSA-9g9p-9gw9-jx7fMODERATE>=10.0.0 <15.5.10 || >=15.6.0-canary.0 <16.1.5

Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

source ↗

GHSA-9gr3-7897-pp7mHIGH>=10.0.0 <11.1.1

XSS in Image Optimization API for Next.js

source ↗

GHSA-9qr9-h5gf-34mpCRITICAL>=14.3.0-canary.77 <15.0.5 || >=15.1.0-canary.0 <15.1.9 || >=15.2.0-canary.0 <15.2.6 || >=15.3.0-canary.0 <15.3.6 || >=15.4.0-canary.0 <15.4.8 || >=15.5.0-canary.0 <15.5.7 || >=16.0.0-canary.0 <16.0.7

Next.js is vulnerable to RCE in React flight protocol

source ↗

GHSA-c4j6-fc7j-m34rHIGH>=13.4.13 <15.5.16 || >=16.0.0 <16.2.5

Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades

source ↗

GHSA-c59h-r6p8-q9wcLOW>=0.9.9 <13.4.20-canary.13

Next.js missing cache-control header may lead to CDN caching empty reply

source ↗

GHSA-f82v-jwr5-mffwCRITICAL>=13.0.0 <13.5.9 || >=14.0.0 <14.2.25 || >=15.0.0 <15.2.3 || >=12.0.0 <12.3.5

Authorization Bypass in Next.js Middleware

source ↗

GHSA-fmvm-x8mv-47mjMODERATE>=10.0.0 <12.1.0

Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.1.0

source ↗

GHSA-fq54-2j52-jc42HIGH>=13.3.1 <13.5.0

Next.js Denial of Service (DoS) condition

source ↗

GHSA-fq77-7p7r-83rjMODERATE>=0.9.9 <9.3.2

Directory Traversal in Next.js

source ↗

GHSA-fr5h-rqp8-mj6gHIGH>=13.4.0 <14.1.1

Next.js Server-Side Request Forgery in Server Actions

source ↗

GHSA-g5qg-72qw-gw5vMODERATE>=0.9.9 <14.2.31 || >=15.0.0 <15.4.5

Next.js Affected by Cache Key Confusion for Image Optimization API Routes

source ↗

GHSA-g77x-44xx-532mMODERATE>=10.0.0 <14.2.7

Denial of Service condition in Next.js image optimization

source ↗

GHSA-ggv3-7p47-pfv8MODERATE>=16.0.0-beta.0 <16.1.7 || >=9.5.0 <15.5.13

Next.js: HTTP request smuggling in rewrites

source ↗

GHSA-gp8f-8m3g-qvj9HIGH>=13.5.1 <13.5.7 || >=14.0.0 <14.2.10

Next.js Cache Poisoning

source ↗

GHSA-gx5p-jg67-6x7hMODERATE>=13.0.0 <15.5.16 || >=16.0.0 <16.2.5

Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

source ↗

GHSA-h27x-g6w4-24gqMODERATE>=16.0.1 <16.1.7

Next.js: Unbounded postponed resume buffering can lead to DoS

source ↗

GHSA-h64f-5h5j-jqjhMODERATE>=10.0.0 <15.5.16 || >=16.0.0 <16.2.5

Next.js has a Denial of Service in the Image Optimization API

source ↗

GHSA-jcc7-9wpm-mj36LOW>=16.0.1 <16.1.7

Next.js: null origin can bypass dev HMR websocket CSRF checks

source ↗

GHSA-m34x-wgrh-g897HIGH>=1.0.0 <4.2.3

Directory traversal vulnerability in Next.js

source ↗

GHSA-m99w-x7hq-7vfjHIGH>=13.0.0 <15.5.21 || >=16.0.0 <16.2.11

Next.js: Denial of Service in App Router using Server Actions

source ↗

GHSA-mg66-mrh9-m8jxHIGH>=15.0.0 <15.5.16 || >=16.0.0 <16.2.5

Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components

source ↗

GHSA-mq59-m269-xvcxMODERATE>=16.0.1 <16.1.7

Next.js: null origin can bypass Server Actions CSRF checks

source ↗

GHSA-mwv6-3258-q52cHIGH>=13.3.0 <14.2.34 || >=15.0.0-canary.0 <15.0.6 || >=15.1.1-canary.0 <15.1.10 || >=15.2.0-canary.0 <15.2.7 || >=15.3.0-canary.0 <15.3.7 || >=15.4.0-canary.0 <15.4.9 || >=15.5.1-canary.0 <15.5.8 || >=15.6.0-canary.0 <15.6.0-canary.59 || >=16.0.0-beta.0 <16.0.9 || >=16.1.0-canary.0 <16.1.0-canary.17

Next Vulnerable to Denial of Service with Server Components

source ↗

GHSA-p9j2-gv94-2wf4HIGH>=12.0.0 <15.5.21 || >=16.0.0 <16.2.11

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

source ↗

GHSA-q4gf-8mx6-v5v3HIGH>=13.0.0 <15.5.15 || >=16.0.0-beta.0 <16.2.3

Next.js has a Denial of Service with Server Components

source ↗

GHSA-q8wf-6r8g-63chMODERATE>=15.5.0 <15.5.21 || >=16.0.0 <16.2.11

Next.js: Denial of Service in the Image Optimization API using SVGs

source ↗

GHSA-qpjv-v59x-3qc4LOW>=0.9.9 <14.2.24 || >=15.0.0 <15.1.6

Next.js Race Condition to Cache Poisoning

source ↗

GHSA-qw96-mm2g-c8m7MODERATE>=7.0.0 <7.0.2

Next.js has cross site scripting (XSS) vulnerability via the 404 or 500 /_error page

source ↗

GHSA-r2fc-ccr8-96c4LOW>=15.3.0 <15.3.3

Next.js has a Cache poisoning vulnerability due to omission of the Vary header

source ↗

GHSA-vfv6-92ff-j949LOW>=13.4.6 <15.5.16 || >=16.0.0 <16.2.5

Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

source ↗

GHSA-vxf5-wxwp-m7g9MODERATE>=0.9.9 <11.1.0

Open Redirect in Next.js

source ↗

GHSA-w37m-7fhw-fmv9MODERATE>=15.0.0-canary.0 <15.0.6 || >=15.1.1-canary.0 <15.1.10 || >=15.2.0-canary.0 <15.2.7 || >=15.3.0-canary.0 <15.3.7 || >=15.4.0-canary.0 <15.4.9 || >=15.5.1-canary.0 <15.5.8 || >=15.6.0-canary.0 <15.6.0-canary.59 || >=16.0.0-beta.0 <16.0.9 || >=16.1.0-canary.0 <16.1.0-canary.17

Next Server Actions Source Code Exposure

source ↗

GHSA-wfc6-r584-vfw7MODERATE>=14.2.0 <15.5.16 || >=16.0.0 <16.2.5

Next.js vulnerable to cache poisoning in React Server Component responses

source ↗

GHSA-wff4-fpwg-qqv3MODERATE>=12.2.3 <12.2.4

Unexpected server crash in Next.js

source ↗

GHSA-wr66-vrwm-5g5xMODERATE>=12.0.0 <12.0.9

Denial of Service Vulnerability in next.js

source ↗

GHSA-x56p-c8cg-q435MODERATE>=9.5.0 <9.5.4

Open Redirect in Next.js versions

source ↗

GHSA-xv57-4mr9-wg8vMODERATE>=0.9.9 <14.2.31 || >=15.0.0 <15.4.5

Next.js Content Injection Vulnerability for Image Optimization

source ↗

GHSA-223j-4rm8-mrmfLOW>=12.3.5 <12.3.6 || >=13.5.9 <13.5.10 || >=14.2.25 <14.2.26 || >=15.2.3 <15.2.4

Next.js may leak x-middleware-subrequest-id to external hosts

source ↗

GHSA-5f7q-jpqc-wp7hMODERATE>=16.0.0-beta.0 <16.1.5 || >=15.0.0-canary.0 <=15.0.0-canary.205 || >=15.0.1-canary.0 <=15.0.1-canary.3 || >=15.0.2-canary.0 <=15.0.2-canary.11 || >=15.0.3-canary.0 <=15.0.3-canary.9 || >=15.0.4-canary.0 <=15.0.4-canary.52 || >=15.1.1-canary.0 <=15.1.1-canary.27 || >=15.2.0-canary.0 <=15.2.0-canary.77 || >=15.2.1-canary.0 <=15.2.1-canary.6 || >=15.2.2-canary.0 <=15.2.2-canary.7 || >=15.3.0-canary.0 <=15.3.0-canary.46 || >=15.3.1-canary.0 <=15.3.1-canary.15 || >=15.4.0-canary.0 <=15.4.0-canary.130 || >=15.4.2-canary.0 <=15.4.2-canary.56 || >=15.5.1-canary.0 <=15.5.1-canary.39 || >=15.6.0-canary.0 <15.6.0-canary.61

Next.js has Unbounded Memory Consumption via PPR Resume Endpoint

source ↗

GHSA-ffhc-5mcf-pf4qMODERATE>=13.4.0 <15.5.16 || >=16.0.0 <16.2.5

Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces

source ↗

GHSA-h25m-26qc-wcjfHIGH>=13.0.0 <15.0.8 || >=15.1.1-canary.0 <15.1.12 || >=15.2.0-canary.0 <15.2.9 || >=15.3.0-canary.0 <15.3.9 || >=15.4.0-canary.0 <15.4.11 || >=15.5.1-canary.0 <15.5.10 || >=15.6.0-canary.0 <15.6.0-canary.61 || >=16.0.0-beta.0 <16.0.11 || >=16.1.0-canary.0 <16.1.5

Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

source ↗

Recent changes

v16.3.0-canary.0Notable

fix(next/image): ensure `images.maximumResponseBody` applies to local images too

source ↗

v16.3.0-canary.0Notable

remove flag guarding `unstable_io`

source ↗

v16.3.0-canary.1Notable

Switch to cargo-binstall and pre-built sccache binaries

source ↗

v16.3.0-canary.1Notable

Redesign blocking route dev overlay and build errors

source ↗

v16.3.0-canary.1Notable

Include prefetch requests in shell upgrade handling for partial fallbacks

source ↗

v16.3.0-canary.1Notable

Improve deduping of concurrent 'use cache' invocations

source ↗

v16.3.0-canary.1Notable

Support more prefetch configuration options

source ↗

v16.3.0-canary.1Breaking

Remove prefetch from instant config

source ↗

v16.3.0-canary.3Notable

Make `'use cache'` fill timeout configurable

source ↗

v16.3.0-canary.3Notable

Restore dev-mode cache-fill timeout for `'use cache'`

source ↗

v16.3.0-canary.3Notable

feat(turbopack): add NEXT_TURBOPACK_TRACING_PATH to control trace output location

source ↗

v16.3.0-canary.3Notable

Turbopack: import.meta.glob docs + edge case support

source ↗

v16.3.0-canary.3Notable

Suspend dynamic route params in dev instant shell

source ↗

v16.3.0-canary.3Notable

[next/image] Stop using deprecated `url.parse`

source ↗

v16.3.0-canary.3Notable

instant(): Block out-of-band client fetches

source ↗

v16.3.0-canary.3Notable

fix(use-cache): remove awaiting revalidation

source ↗

v16.3.0-canary.3Notable

Strengthen _rsc cache-busting param

source ↗

v16.3.0-canary.3Notable

Auto-generate AGENTS.md / CLAUDE.md in next dev

source ↗

v16.3.0-canary.3Notable

Upgrade React from `fef12a01-20260413` to `da9325b5-20260417`

source ↗

v16.3.0-canary.3Notable

New ESLint rule: `no-location-assign-relative-destination`

source ↗

v16.3.0-canary.4Notable

Preserve `__NEXT_ERROR_CODE` across the `/_error` page handoff

source ↗

v16.3.0-canary.5Notable

Fix `export * as X from './self'` in scope-hoisted modules

source ↗

v16.3.0-canary.5Notable

HMR: debounce status indicator transitions to prevent flicker during bursts of changes

source ↗

v16.3.0-canary.5Notable

Forward invalid dynamic usage errors on client-side navigations

source ↗

v16.3.0-canary.5Notable

Fix route handler SWR blocking on Node runtime

source ↗

v16.3.0-canary.5Notable

Apply sourcemaps by default during prerender in `next build`

source ↗

v16.3.0-canary.6Notable

enable validateRSCRequestHeaders by default

source ↗

v16.3.0-canary.6Notable

fix: handling of falsey values in error boundaries

source ↗

v16.3.0-canary.6Notable

[next/image] Only fire `onError` once

source ↗

v16.3.0-canary.6Notable

Enable server HMR for metadata routes (manifest.ts, robots.ts, etc.)

source ↗

Check what changed for next since your installed version, live.

Open the playground →