← Back to Resources
Open Source NewsSeptember 22, 20262 min read

Critical Security Update: v16.3.6 and v15.5.26

By BIOS Founding Team

Critical Security Update: v16.3.6 and v15.5.26

An out-of-band critical security release patching a remote-code-execution vulnerability in the Node.js ImageResponse implementation, caused by improper SVG-output escaping in an upstream dependency.

Next.js versions 16.2.0 through 16.3.5 are affected; the Edge ImageResponse implementation is not affected. Users are urged to upgrade to 16.3.6 or 15.5.26 immediately.

Full details: https://nextjs.org/blog/nextjs-security-update-september-22-2026