August 2026 Security Release
Next.js 16.3.3 and 15.5.24 fix two critical unauthenticated remote-code-execution paths. One is triggered when the Image Optimization API processes an attacker-controlled AVIF through libheif; the releases disable AVIF optimization while an upstream fix propagates. The other affects Windows servers using both the Pages Router and App Router without Cache Components. Linux and macOS are unaffected by that path, but affected Windows deployments have no workaround. Teams should patch rather than attempt configuration-only mitigation.