Catalog / Frontend

Next.js changelog

Next.js is at 16.4.0, published 7 Oct 2026, 4 days ago.

React framework that handles routing, rendering and build output for production sites.

SubscribeNext.js as markdown, for pasting into a model
Collected
39 releases back to 4 Feb 2026
Source
vercel/next.js
Project
nextjs.org
Advisories
69 published newest 2026
Feed
RSS

Read on 28 of the 30 days on record, last today. Collection status

Version history

16.x24 releases
16.4.0

Check out the 16.4 announcement post to get an overview of the changes. Core Changes Show compiler plugin warning in more situations: #75682 fix(scripts): correct typo in rm.mjs error message: #87015 docs: improve clarity and punctuation in

addedfixedchanged
16.3.8

This release contains security fixes for the following advisories: High: Server-Side Request Forgery in Image Optimization Medium: Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass Cache poisoning o

securityfixed
16.3.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#98931) Credits Huge thanks to @lukesandbe

fixed
16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

security
16.3.5

The following bug fixes have been backported. It does not include all pending features/changes on canary. next/image: Skip 0-byte entries when initializing disk LRU cache (#98185) next/image: Reject empty images when reading/writing to the

addedfixed
16.3.4

Follow-up release to v16.3.3 re-enabling AVIF Image Optimization (#97949). The following bug fixes have been backported. It does not include all pending features/changes on canary. testmode: Fix infinite recursion in testmode passthrough fe

fixed
16.3.3

This release contains security fixes for the following advisories: Critical: Unauthenticated Remote Code Execution on windows-hosted servers Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

securityfixed
16.3.2

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes [backport] Scope app-entry export validation to files inside the app directory (#97357) [backport] Fix catch-all index p

fixed
16.3.1

[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by @lukesandberg in https://github.com/vercel/next.js/pull/96653 [16.x] [turbopack] Add turbopack_ecmascript and turbopack_wasm's embeded FS to internal_assets_co

addedchanged
16.3.0

Check out the 16.3 announcement post to get an overview of the changes. Core Changes Update vendored lodash to 4.17.23 to fix CVE-2025-13465: #91558 Fix invalid HTML response for route-level RSC requests in deployment adapter: #91541 Normal

securityaddedfixed
16.2.12

Backport/docs fixes 16.2 - July round by @icyJoseph in https://github.com/vercel/next.js/pull/96031 [Backport] Fixes to support TypeScript 7 by @lukesandberg in https://github.com/vercel/next.js/pull/95831

fixedchanged
16.2.11

This release contains security fixes for the following advisories: High: Denial of Service in App Router using Server Actions Middleware / Proxy bypass in App Router applications using Turbopack and single locale Server-Side Request Forgery

securityfixed
16.2.10

Contains no changes except publishing @next/swc-wasm-web which was accidentally not published since 16.2.4.

16.2.9

Empty release to ensure next@latest points at a stable release. Next.js only allows publishing with Trusted Publishing enabled. In order to fix NPM dist-tags, we have to release a new version. Updating dist-tags is not possible with Trusted

added
16.2.8

Release with no changes in an attempt to fix next@latest pointing at a prerelease version.

16.2.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes Backport documentation fixes for v16.2 (#93804) [backport] Patch playwright-core to resolve _finishedPromise on requestF

addedfixed
16.2.6

[!NOTE] This release contains security fixes and backported bug fixes. It does not include all pending features/changes on canary. Security Fixes The following advisories have been addressed: High: GHSA-8h8q-6873-q5fj: Denial of Service wit

securityfixed
16.2.5

[!NOTE] This release contains security fixes and backported bug fixes. It does not include all pending features/changes on canary. Security Fixes The following advisories have been addressed: High: GHSA-8h8q-6873-q5fj: Denial of Service wit

securityfixed
16.2.4

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes chore: Bump reqwest to 0.13.2 (Fixes Google Fonts with Turbopack for Windows on ARM64) (#92713) Turbopack: fix filesyste

fixed
16.2.3

[!NOTE] This release is backporting security and bug fixes. For more information about the fixed security vulnerability, please see https://vercel.com/changelog/summary-of-cve-2026-23869. The release does not include all pending features/ch

securityfixed
16.2.2

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes backport: Move expanded adapters docs to API reference (#92115) (#92129) Backport: TypeScript v6 deprecations for baseUr

fixed
16.2.1

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes docs: post release amends (#91715) docs: fix broken Activity Patterns demo link in preserving UI state guide (#91698) Fi

fixed
16.2.0

[!TIP]Check out our Next v16.2 Blog Post to learn more about this release. Core Changes Upgrade React from f93b9fd4-20251217 to 65eec428-20251218: #87323 Turbopack: Create junction points instead of symlinks on Windows: #87606 Turbopack: Sy

securityaddedfixed
16.1.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes [Cache Components] Prevent streaming fetch calls from hanging in dev (#89194) Apply server actions transform to node_mod

securityaddedfixed
15.x15 releases
15.5.27

This release contains security fixes for the following advisories: Medium: Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass Cache poisoning of SSG and ISR pages in self-hosted Next.js applications

securityfixed
15.5.26

This release contains additional security hardening for next/og. For more information, check out https://nextjs.org/blog/nextjs-security-update-september-22-2026

securitychanged
15.5.25

Follow-up release to v15.5.24 re-enabling AVIF Image Optimization when newer versions of sharp are installed (#97954).

15.5.24

This release contains security fixes for the following advisories: Critical: Unauthenticated Remote Code Execution on windows-hosted servers Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

securityfixed
15.5.23

[15.x] Port ReplyServer traversal guards to FlightClient @eps1lon in https://github.com/vercel/next.js/pull/96405

changed
15.5.22

[15.5] Reject TypeScript >= 7.0 with an actionable error by @lukesandberg in https://github.com/vercel/next.js/pull/96110

changed
15.5.21

This release contains security fixes for the following advisories: High: Denial of Service in App Router using Server Actions Middleware / Proxy bypass in App Router applications using Turbopack and single locale Server-Side Request Forgery

securityfixed
15.5.20

Contains no changes except publishing @next/swc-wasm-web which was accidentally not published since 15.5.15.

15.5.19

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes [15.5.x] Don't drop FormData entries (#94244) Other [15.5.x] Fix CI (#94281) Credits Huge thanks to @eps1lon for helping

fixed
15.5.18

This release contains security fixes for the following advisories: High: GHSA-8h8q-6873-q5fj: Denial of Service with Server Components GHSA-267c-6grr-h53f: Middleware / Proxy bypass in App Router applications via segment-prefetch routes GHS

securityfixed
15.5.16

This release contains security fixes for the following advisories: High: GHSA-8h8q-6873-q5fj: Denial of Service with Server Components GHSA-267c-6grr-h53f: Middleware / Proxy bypass in App Router applications via segment-prefetch routes GHS

securityfixed
15.5.15

Please refer the following changelogs for more information about this security release: https://vercel.com/changelog/summary-of-cve-2026-23869

security
15.5.14

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes feat(next/image): add lru disk cache and images.maximumDiskCacheSize (#91660) Fix(pages-router): restore Content-Length

addedfixed
15.5.13

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes fix: patch http-proxy to prevent request smuggling in rewrites (See: CVE-2026-29057) Credits Huge thanks to @ztanner for

securityfixed
15.5.12

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. fix unlock in publish-native This is a re-release of v15.5.11 applying the turbopack changes.

fixed