Next.js 15 End of Life (Oct 21, 2026): CVE Exposure and the Upgrade Path to 16

Next.js 15 reaches end of life on October 21, 2026. Here's how that date is derived, which 2026 vulnerabilities hit self-hosted apps but not Vercel, what breaks on the move to Next.js 16, and what to do if you can't upgrade in time.
Next.js 15 reaches end of life on October 21, 2026, two years after its October 21, 2024 release, when it leaves Maintenance LTS and stops receiving guaranteed security patches. Your app won't stop running, but vulnerabilities disclosed after that date have no committed fix for 15.x. If you self-host Next.js 14 or 15, patch to the latest 15.5.x now and schedule the move to Next.js 16, which the same two-year rule keeps supported until October 21, 2027.
When does Next.js 15 reach end of life?
Next.js 15 reaches end of life on October 21, 2026. The Next.js support policy doesn't print that date; it states a rule: “Each major version will remain in Maintenance LTS for two years following the initial release.” Version 15.x shipped October 21, 2024, so the rule ends its support on October 21, 2026. Trackers endoflife.ai and HeroDevs reach the same date.
| Major | Released | Status on Oct 10, 2026 | Support ends |
|---|---|---|---|
| 16.x | Oct 21, 2025 | Active LTS | Oct 21, 2027 (derived) |
| 15.x | Oct 21, 2024 | Maintenance LTS | Oct 21, 2026 (derived) |
| 14.x | Oct 26, 2023 | Unsupported | Oct 26, 2025 (derived) |
Every 2026 security release we reviewed shipped its 15.x fix only as a 15.5.x patch, so an app pinned to 15.0 through 15.4 is already unpatched. The policy also allows patches outside LTS only “in rare circumstances, depending on the severity of the underlying bug,” which is not something to plan around.
Is Next.js 14 still supported, and is it vulnerable?
No. Next.js 14 is listed as unsupported in the support policy, and its two-year window closed on October 26, 2025. It is also exposed: at least three 2026 advisories include 14.x in their affected ranges, with fixes shipped only for 15.5.x and 16.x.
- CVE-2026-44578 (High, CVSS 8.6): server-side request forgery (SSRF) via crafted WebSocket upgrade requests, affecting 13.4.13 up to 15.5.16. The GitHub advisory limits it to self-hosted apps on the built-in Node.js server: “Vercel-hosted deployments are not affected.”
- GHSA-2xp9-vwfh-vxw4 (Critical): unauthenticated remote code execution (RCE) when the Image Optimization API processes a crafted AVIF file, affecting 10.0.0 up to 15.5.24 per Netlify's changelog.
- CVE-2026-75604 (Critical): unauthenticated RCE on Windows-hosted servers, affecting 13.4.0 up to 15.5.24 per the same changelog.
Not every advisory reaches back that far: GHSA-4jqv-mc3x-m676, September's cache-poisoning issue, lists only 15.0.0 and later. For a 14.x app, though, the answer is clear: two critical RCEs have no upstream fix on your line.
Which 2026 Next.js vulnerabilities hit self-hosted apps but not Vercel?
Since July 13, 2026, Next.js has pre-announced its security releases, roughly monthly. The lead time lets the team coordinate with hosting providers “to deploy mitigations, such as firewall rules, that help protect applications that haven't been patched yet.” Self-hosted teams get the notice; the mitigation is on you.
The July release fixed 9 vulnerabilities (4 high, 5 medium), August's fixed two critical unauthenticated RCEs, and September's fixed 7 (1 high, 5 medium, 1 low): 18 across three monthly releases. An out-of-band update is planned for October 14 for three upstream-dependency vulnerabilities, two critical and one high.
These 2026 issues depend on how you host:
| Vulnerability | Severity | Patched in (16.x / 15.5.x) | Self-hosted only? | Condition or note |
|---|---|---|---|---|
| CVE-2026-44578: WebSocket-upgrade SSRF | High (CVSS 8.6) | 16.2.5 / 15.5.16 | Yes, per advisory | Built-in Node.js server |
| CVE-2026-64649: Server Actions SSRF | High | 16.2.11 / 15.5.21 | Custom servers | Attacker controls Host-associated headers |
| CVE-2026-64644: image optimizer SVG DoS | Medium | 16.2.11 / 15.5.21 | Yes, default loader | Remote images enabled |
| GHSA-2xp9-vwfh-vxw4: AVIF RCE | Critical | 16.3.3 / 15.5.24 | Where Next.js's own optimizer runs | Netlify's image CDN bypasses it |
| CVE-2026-75604: Windows RCE | Critical | 16.3.3 / 15.5.24 | Windows hosts only | Pages + App Router, no Cache Components |
| CVE-2026-94483: image SSRF | High | 16.3.8 / 15.5.27 | Not stated | Only with images.remotePatterns set |
| CVE-2026-94543: SSG/ISR cache poisoning | Medium | 16.3.8 / 15.5.27 | Yes; Vercel not affected | Pages Router SSG/ISR |
The pattern: the image optimizer, built-in server, custom servers and self-hosted response cache are surfaces a managed platform typically replaces. Self-host, and they're yours to patch and firewall.
Should you upgrade to Next.js 16 or stay on 15.5?
For almost every self-hosted app, upgrade to 16. Staying on 15.5 keeps you patched until October 21, 2026; 16 keeps you patched until October 21, 2027 under the same two-year rule. The current minor is Next.js 16.4, released October 6, 2026.
Every major since 12.x shipped in October, and no 17 had been announced as of October 10; if it lands, 16 moves to Maintenance LTS, which still covers security patches. The October 14 update is the last announced release before 15's window closes; whether 15.5.x gets a build isn't known yet.
Staying on 15.5 briefly is defensible, with an exit date, if:
- You run Partial Prerendering on a 15 canary; the upgrade guide says to stay there, then migrate to
cacheComponents. - Synchronous
cookies(),headers()orparamsaccess is still widespread. Version 15 tolerates it with warnings; 16 removes it. - A critical dependency hasn't shipped Next.js 16 compatibility.
Don't let bundler security drive the choice: September's CVE-2026-94485 hit only webpack builds, while July's CVE-2026-64642 middleware bypass required a Turbopack build with a single locale.
What breaks when you upgrade from Next.js 15 to 16?
Run npx @next/codemod@canary upgrade latest, then work through the version 16 upgrade guide. These changes are the most likely to bite a self-hosted deployment:
- Node.js 20.9+ and TypeScript 5.1+. Node.js 18 is dropped. Update Docker base images and CI runners first.
- Synchronous request APIs are gone.
cookies(),headers(),draftMode(),paramsandsearchParamsmust be awaited. Theupgradecodemod doesn't cover this; runnpx @next/codemod@canary next-async-request-api .separately. middlewarebecomesproxy. Rename the file and exported function. Proxy runs only on Node.js; keep edge-runtime middleware asmiddleware, which still works but is deprecated.- Turbopack is the default.
next buildfails if it finds a webpack config, including one a plugin injects. Migrate to top-levelturbopackoptions or build with--webpack. - Runtime config is removed.
serverRuntimeConfigandpublicRuntimeConfigare gone, breaking build-once, deploy-many Docker images that used them. Read environment variables at request time afterawait connection();NEXT_PUBLIC_values are inlined at build time and can't vary per environment. - Image defaults tighten.
minimumCacheTTLrises from 60 seconds to 4 hours, so a CMS image replaced at the same URL can stay stale for hours.qualitiesdefaults to[75], and local-IP optimization is blocked unless you setdangerouslyAllowLocalIP, which can cause 400s in VPCs with split-horizon DNS. - New build and type errors. Parallel route slots need an explicit
default.js, and single-argumentrevalidateTag()is now a TypeScript error. - Removals.
next lint, AMP and theexperimental.dynamicIOandexperimental.useCacheflags are gone, andnext buildno longer lints.
How do you migrate from Next.js 14 to 16?
In two hops, with a production deploy between them. Hop one, 14 to the latest 15.5.x, puts you on a patched line, if only until October 21, and 15 still tolerates synchronous request-API access, so you can ship before every call site is converted. Hop two, 15.5 to 16, removes that safety net and adds the version 16 breaking changes (Node.js 20.9+, proxy, Turbopack by default).
The 14-to-15 hop is hard because of behavior, not syntax:
- React 19 is the minimum. Libraries with React 18 peer ranges can block the install.
- Caching defaults flip.
fetchrequests andGETroute handlers are no longer cached by default, and page segments aren't reused from the client cache. Self-hosted, that can mean more origin and CMS load until you opt routes back in. - Async request APIs arrive. Run the codemod on this hop, while the synchronous fallback keeps unconverted call sites working.
Effort triage: 15.5 to 16 is one hop of mostly build and config work. 14 to 16 is two hops, and the first is riskier because caching regressions surface in production traffic, not in a failed build. Upgrade Node.js to 20.9+ as a separate change before either hop.
What are your options if you can't upgrade before October 21?
There are four, and a realistic plan usually pairs a bridge with a destination.
| Option | Fits when | Effort and cost | Residual risk |
|---|---|---|---|
| Upgrade to 16 now | You're on 15.5 with async APIs migrated | One hop, mostly build and config | Lowest: patched to Oct 21, 2027 |
| Extended support (e.g. HeroDevs NES) | Many legacy apps or a compliance deadline | Commercial contract; registry swap and rebuild | Bounded by the vendor's patch scope; migration still due |
| Managed hosting | You want the platform to own the optimizer, server and firewall | A migration of its own, plus hosting spend | Removes some self-hosted-only CVEs, not framework EOL |
| Compensating controls | A bridge of weeks, not months | Low to moderate ops work | Highest: future CVEs stay unpatched |
HeroDevs describes NES for Next.js as a “drop-in replacement for EOL Next.js versions” with “continued security patches delivered the day OSS support ends”; confirm which versions and advisories it covers before signing. Managed hosting changes the threat surface, not the support status: Netlify says its sites never invoke Next.js's own image optimizer.
For the bridge, these controls map to the 2026 advisories:
- Shrink the image surface. Remove or tighten
images.remotePatterns; CVE-2026-94483 doesn't affect apps without them. If you don't need runtime optimization, use a CDN loader orimages.unoptimizedand block/_next/imageat the proxy. - Harden the origin. Per the CVE-2026-44578 advisory: don't expose the server directly to untrusted networks, block WebSocket upgrades at the reverse proxy if unused, and restrict outbound access to internal networks and metadata services.
- Put a WAF in front and confirm your vendor ships rules for Next.js advisories.
- Run on Linux. CVE-2026-75604 has “no known workaround for affected Windows-hosted applications.”
- Pin the latest 15.5.x patch and watch for the October 14 advisories.
FAQ
Is Next.js 16 LTS?
Yes. The support policy lists 16.x as Active LTS, with features, bug fixes and security patches. When the next major ships, 16 moves to Maintenance LTS, and the two-year rule ends its support on October 21, 2027.
Can you disable Turbopack in Next.js 16?
Yes, with the --webpack flag, for example next build --webpack. Without it, next build fails when it finds a webpack config, including one a plugin adds. The Next.js team recommends Turbopack for development and production.
Does Vercel patch old Next.js versions?
Not beyond the Next.js support policy. Only 16.x and 15.x are covered today, and in 2026 the 15.x fixes shipped only on 15.5.x. Older versions get patches only “in rare circumstances.” Platform-side firewall rules protect hosted apps, not your self-hosted build.
Will my Next.js 15 app stop working on October 21?
No. Your app keeps building, deploying and serving traffic. What ends is the commitment to fix new vulnerabilities on 15.x, and with security releases now roughly monthly, unpatched exposure accumulates quickly.
Get an upgrade-readiness assessment
Synchronized Codelab runs its own production site on Next.js and Strapi, so we track these releases closely. Our upgrade-readiness assessment for self-hosted Next.js 14 and 15 apps maps your deployment against each 2026 advisory, lists what breaks on the move to 16, and gives you a sequenced plan with an effort estimate. If you need a decision before October 21, talk to us.