Is your Next.js app exposed to CVE-2026-94545?

CVE-2026-94545 affects Next.js 16.2.0 through 16.3.5 when ImageResponse from next/og runs on the Node.js runtime.

Next.js 15 and the Edge implementation of ImageResponse are not affected by the remote code execution issue.

Upgrading to Next.js 16.3.6 fixes the flaw, and no patched 16.2 release exists.

Read the full post

Read the full post