Next.js 15 End of Life (Oct 21, 2026): CVE Exposure and the Upgrade Path to 16

Image for Next.js 15 End of Life (Oct 21, 2026): CVE Exposure and the Upgrade Path to 16

Synchronized Codelab

Next.js 15 reaches end of life on October 21, 2026. Here's how that date is derived, which 2026 vulnerabilities hit self-hosted apps but not Vercel, what breaks on the move to Next.js 16, and what to do if you can't upgrade in time.

Next.js 15 reaches end of life on October 21, 2026, two years after its October 21, 2024 release, when it leaves Maintenance LTS and stops receiving guaranteed security patches. Your app won't stop running, but vulnerabilities disclosed after that date have no committed fix for 15.x. If you self-host Next.js 14 or 15, patch to the latest 15.5.x now and schedule the move to Next.js 16, which the same two-year rule keeps supported until October 21, 2027.

When does Next.js 15 reach end of life?

Next.js 15 reaches end of life on October 21, 2026. The Next.js support policy doesn't print that date; it states a rule: “Each major version will remain in Maintenance LTS for two years following the initial release.” Version 15.x shipped October 21, 2024, so the rule ends its support on October 21, 2026. Trackers endoflife.ai and HeroDevs reach the same date.

MajorReleasedStatus on Oct 10, 2026Support ends
16.xOct 21, 2025Active LTSOct 21, 2027 (derived)
15.xOct 21, 2024Maintenance LTSOct 21, 2026 (derived)
14.xOct 26, 2023UnsupportedOct 26, 2025 (derived)

Every 2026 security release we reviewed shipped its 15.x fix only as a 15.5.x patch, so an app pinned to 15.0 through 15.4 is already unpatched. The policy also allows patches outside LTS only “in rare circumstances, depending on the severity of the underlying bug,” which is not something to plan around.

Is Next.js 14 still supported, and is it vulnerable?

No. Next.js 14 is listed as unsupported in the support policy, and its two-year window closed on October 26, 2025. It is also exposed: at least three 2026 advisories include 14.x in their affected ranges, with fixes shipped only for 15.5.x and 16.x.

  • CVE-2026-44578 (High, CVSS 8.6): server-side request forgery (SSRF) via crafted WebSocket upgrade requests, affecting 13.4.13 up to 15.5.16. The GitHub advisory limits it to self-hosted apps on the built-in Node.js server: “Vercel-hosted deployments are not affected.”
  • GHSA-2xp9-vwfh-vxw4 (Critical): unauthenticated remote code execution (RCE) when the Image Optimization API processes a crafted AVIF file, affecting 10.0.0 up to 15.5.24 per Netlify's changelog.
  • CVE-2026-75604 (Critical): unauthenticated RCE on Windows-hosted servers, affecting 13.4.0 up to 15.5.24 per the same changelog.

Not every advisory reaches back that far: GHSA-4jqv-mc3x-m676, September's cache-poisoning issue, lists only 15.0.0 and later. For a 14.x app, though, the answer is clear: two critical RCEs have no upstream fix on your line.

Which 2026 Next.js vulnerabilities hit self-hosted apps but not Vercel?

Since July 13, 2026, Next.js has pre-announced its security releases, roughly monthly. The lead time lets the team coordinate with hosting providers “to deploy mitigations, such as firewall rules, that help protect applications that haven't been patched yet.” Self-hosted teams get the notice; the mitigation is on you.

The July release fixed 9 vulnerabilities (4 high, 5 medium), August's fixed two critical unauthenticated RCEs, and September's fixed 7 (1 high, 5 medium, 1 low): 18 across three monthly releases. An out-of-band update is planned for October 14 for three upstream-dependency vulnerabilities, two critical and one high.

These 2026 issues depend on how you host:

VulnerabilitySeverityPatched in (16.x / 15.5.x)Self-hosted only?Condition or note
CVE-2026-44578: WebSocket-upgrade SSRFHigh (CVSS 8.6)16.2.5 / 15.5.16Yes, per advisoryBuilt-in Node.js server
CVE-2026-64649: Server Actions SSRFHigh16.2.11 / 15.5.21Custom serversAttacker controls Host-associated headers
CVE-2026-64644: image optimizer SVG DoSMedium16.2.11 / 15.5.21Yes, default loaderRemote images enabled
GHSA-2xp9-vwfh-vxw4: AVIF RCECritical16.3.3 / 15.5.24Where Next.js's own optimizer runsNetlify's image CDN bypasses it
CVE-2026-75604: Windows RCECritical16.3.3 / 15.5.24Windows hosts onlyPages + App Router, no Cache Components
CVE-2026-94483: image SSRFHigh16.3.8 / 15.5.27Not statedOnly with images.remotePatterns set
CVE-2026-94543: SSG/ISR cache poisoningMedium16.3.8 / 15.5.27Yes; Vercel not affectedPages Router SSG/ISR

The pattern: the image optimizer, built-in server, custom servers and self-hosted response cache are surfaces a managed platform typically replaces. Self-host, and they're yours to patch and firewall.

Should you upgrade to Next.js 16 or stay on 15.5?

For almost every self-hosted app, upgrade to 16. Staying on 15.5 keeps you patched until October 21, 2026; 16 keeps you patched until October 21, 2027 under the same two-year rule. The current minor is Next.js 16.4, released October 6, 2026.

Every major since 12.x shipped in October, and no 17 had been announced as of October 10; if it lands, 16 moves to Maintenance LTS, which still covers security patches. The October 14 update is the last announced release before 15's window closes; whether 15.5.x gets a build isn't known yet.

Staying on 15.5 briefly is defensible, with an exit date, if:

  • You run Partial Prerendering on a 15 canary; the upgrade guide says to stay there, then migrate to cacheComponents.
  • Synchronous cookies(), headers() or params access is still widespread. Version 15 tolerates it with warnings; 16 removes it.
  • A critical dependency hasn't shipped Next.js 16 compatibility.

Don't let bundler security drive the choice: September's CVE-2026-94485 hit only webpack builds, while July's CVE-2026-64642 middleware bypass required a Turbopack build with a single locale.

What breaks when you upgrade from Next.js 15 to 16?

Run npx @next/codemod@canary upgrade latest, then work through the version 16 upgrade guide. These changes are the most likely to bite a self-hosted deployment:

  1. Node.js 20.9+ and TypeScript 5.1+. Node.js 18 is dropped. Update Docker base images and CI runners first.
  2. Synchronous request APIs are gone. cookies(), headers(), draftMode(), params and searchParams must be awaited. The upgrade codemod doesn't cover this; run npx @next/codemod@canary next-async-request-api . separately.
  3. middleware becomes proxy. Rename the file and exported function. Proxy runs only on Node.js; keep edge-runtime middleware as middleware, which still works but is deprecated.
  4. Turbopack is the default. next build fails if it finds a webpack config, including one a plugin injects. Migrate to top-level turbopack options or build with --webpack.
  5. Runtime config is removed. serverRuntimeConfig and publicRuntimeConfig are gone, breaking build-once, deploy-many Docker images that used them. Read environment variables at request time after await connection(); NEXT_PUBLIC_ values are inlined at build time and can't vary per environment.
  6. Image defaults tighten. minimumCacheTTL rises from 60 seconds to 4 hours, so a CMS image replaced at the same URL can stay stale for hours. qualities defaults to [75], and local-IP optimization is blocked unless you set dangerouslyAllowLocalIP, which can cause 400s in VPCs with split-horizon DNS.
  7. New build and type errors. Parallel route slots need an explicit default.js, and single-argument revalidateTag() is now a TypeScript error.
  8. Removals. next lint, AMP and the experimental.dynamicIO and experimental.useCache flags are gone, and next build no longer lints.

How do you migrate from Next.js 14 to 16?

In two hops, with a production deploy between them. Hop one, 14 to the latest 15.5.x, puts you on a patched line, if only until October 21, and 15 still tolerates synchronous request-API access, so you can ship before every call site is converted. Hop two, 15.5 to 16, removes that safety net and adds the version 16 breaking changes (Node.js 20.9+, proxy, Turbopack by default).

The 14-to-15 hop is hard because of behavior, not syntax:

  • React 19 is the minimum. Libraries with React 18 peer ranges can block the install.
  • Caching defaults flip. fetch requests and GET route handlers are no longer cached by default, and page segments aren't reused from the client cache. Self-hosted, that can mean more origin and CMS load until you opt routes back in.
  • Async request APIs arrive. Run the codemod on this hop, while the synchronous fallback keeps unconverted call sites working.

Effort triage: 15.5 to 16 is one hop of mostly build and config work. 14 to 16 is two hops, and the first is riskier because caching regressions surface in production traffic, not in a failed build. Upgrade Node.js to 20.9+ as a separate change before either hop.

What are your options if you can't upgrade before October 21?

There are four, and a realistic plan usually pairs a bridge with a destination.

OptionFits whenEffort and costResidual risk
Upgrade to 16 nowYou're on 15.5 with async APIs migratedOne hop, mostly build and configLowest: patched to Oct 21, 2027
Extended support (e.g. HeroDevs NES)Many legacy apps or a compliance deadlineCommercial contract; registry swap and rebuildBounded by the vendor's patch scope; migration still due
Managed hostingYou want the platform to own the optimizer, server and firewallA migration of its own, plus hosting spendRemoves some self-hosted-only CVEs, not framework EOL
Compensating controlsA bridge of weeks, not monthsLow to moderate ops workHighest: future CVEs stay unpatched

HeroDevs describes NES for Next.js as a “drop-in replacement for EOL Next.js versions” with “continued security patches delivered the day OSS support ends”; confirm which versions and advisories it covers before signing. Managed hosting changes the threat surface, not the support status: Netlify says its sites never invoke Next.js's own image optimizer.

For the bridge, these controls map to the 2026 advisories:

  • Shrink the image surface. Remove or tighten images.remotePatterns; CVE-2026-94483 doesn't affect apps without them. If you don't need runtime optimization, use a CDN loader or images.unoptimized and block /_next/image at the proxy.
  • Harden the origin. Per the CVE-2026-44578 advisory: don't expose the server directly to untrusted networks, block WebSocket upgrades at the reverse proxy if unused, and restrict outbound access to internal networks and metadata services.
  • Put a WAF in front and confirm your vendor ships rules for Next.js advisories.
  • Run on Linux. CVE-2026-75604 has “no known workaround for affected Windows-hosted applications.”
  • Pin the latest 15.5.x patch and watch for the October 14 advisories.

FAQ

Is Next.js 16 LTS?

Yes. The support policy lists 16.x as Active LTS, with features, bug fixes and security patches. When the next major ships, 16 moves to Maintenance LTS, and the two-year rule ends its support on October 21, 2027.

Can you disable Turbopack in Next.js 16?

Yes, with the --webpack flag, for example next build --webpack. Without it, next build fails when it finds a webpack config, including one a plugin adds. The Next.js team recommends Turbopack for development and production.

Does Vercel patch old Next.js versions?

Not beyond the Next.js support policy. Only 16.x and 15.x are covered today, and in 2026 the 15.x fixes shipped only on 15.5.x. Older versions get patches only “in rare circumstances.” Platform-side firewall rules protect hosted apps, not your self-hosted build.

Will my Next.js 15 app stop working on October 21?

No. Your app keeps building, deploying and serving traffic. What ends is the commitment to fix new vulnerabilities on 15.x, and with security releases now roughly monthly, unpatched exposure accumulates quickly.

Get an upgrade-readiness assessment

Synchronized Codelab runs its own production site on Next.js and Strapi, so we track these releases closely. Our upgrade-readiness assessment for self-hosted Next.js 14 and 15 apps maps your deployment against each 2026 advisory, lists what breaks on the move to 16, and gives you a sequenced plan with an effort estimate. If you need a decision before October 21, talk to us.