CVE-2026-94545 affects Next.js 16.2.0 through 16.3.5 when ImageResponse from next/og runs on the Node.js runtime.
Next.js 15 and the Edge implementation of ImageResponse are not affected by the remote code execution issue.
Upgrading to Next.js 16.3.6 fixes the flaw, and no patched 16.2 release exists.