BetaWeekly digests are a beta — we're trying something new. Feedback welcome.
Next.js patches critical SSRF and cache flaws as SvelteKit 3 lands
September 28 – October 4, 2026
Security took center stage this week as Next.js patched a high-severity server-side request forgery in Image Optimization alongside a range of cache-poisoning fixes across two release lines, while SvelteKit shipped its long-awaited 3.0 major with a coordinated wave of rewritten adapters.
Next.js closes a high-severity SSRF and a cluster of cache flaws
Vercel's framework had an unusually heavy security week, and the fixes spanned both the current and previous major lines. The headline is a high-severity server-side request forgery in Image Optimization, patched together with five medium-severity issues: cache poisoning of SSG and ISR pages, cross-user content substitution, Draft Mode content leaking into persisted pages through a pending use cache fill, and a cache leak across root param values in nested use cache functions. A low-severity information-disclosure bug in the development server's Model Context Protocol endpoint was fixed alongside them.
Projects still on the older line aren't stranded — the same fixes, minus the SSRF, arrived as cache-poisoning patches for SSG and ISR on the previous major, covering the metadata image-route disclosure and the persistent denial-of-service variant of the cache bug. If you self-host, this is the week to take both.
Underneath the security work, the canary line kept moving on Turbopack and caching. New projects scaffolded from the canary now get Cache Components enabled by default in create-next-app, and the shared Turbopack runtime is enabled by default with stabilized ensureStatic. Elsewhere: Draft Mode no longer leaks through cross-request use cache deduplication, with response cache keys now scoped to their source route and DNS pinned when fetching external images; navigation() and prefetch() lost their unstable_ prefix, a breaking rename worth grepping for; export name mangling is on by default for Turbopack builds alongside a new unstable parameter-matching API; and client params no longer suspend on shallow URL updates, killing an unnecessary Suspense fallback. A strongly consistent read that could hang on a canceled task was backported to the stable line, and the bundle analyzer picked up unified delta colors and a route summary over a reworked module cache.
SvelteKit 3 arrives, with every adapter rewritten
The week's other big story: SvelteKit 3 is here, the framework's first major in years. The theme is polish and type safety rather than reinvention, with an sv migrate command smoothing the upgrade. Breaking changes include remote function types moving to $app/server, synchronous getRequest/setResponse, and a TypeScript 6 minimum, plus the removal of the experimental.handleRenderingErrors flag.
The release pulled a coordinated version bump across the whole adapter ecosystem, most of which now requires SvelteKit 3 and populates env vars before instrumentation.server.js is evaluated. Several adapters moved to rolldown for bundling, including Vercel's edge bundling on an es2022 target and Netlify's output conforming to the stable Frameworks API. The Cloudflare adapter raised its Wrangler floor, the Bun adapter gained a native static-serving mode on Bun 1.4, the static adapter started matching adapter-vercel's prerendered redirect handling, and adapter-auto added zero-config deploys for Render. Tooling kept pace: @sveltejs/package now warns on server-only files used without a server-only import, and @sveltejs/enhanced-img moved to Vite 8 and vite-plugin-svelte 7. In the run-up, the team shipped a stream of fixes across one pre-release that closed an enhanced-form cross-origin navigation and escaped cache-control headers in prerendered HTML, another that fixed scrollRestoration surviving back/forward cache restores and clearing navigating on aborted popstate, and a Cloudflare adapter patch disposing the platform proxy on server close. The monthly roundup captures the final changes before 3.0 and sv hitting 1.0.
Expo sharpens simulator and update workflows
EAS CLI's two releases this week both target the inner loop. eas simulator can now record HTTP(S) traffic from apps on the device, with a companion flag for keeping headers, query values, and bodies — a genuine debugging upgrade for network issues that only reproduce on-device. Separately, eas update gained source-map uploads for stack-trace symbolication and a force-end-rollout flag, with embedded bundle uploads after build now on by default for SDK 58+ projects and App Store Connect token reuse fixed.
Releases covered28
- SvelteKit 3 is here (opens in new tab)
- @sveltejs/kit@3.0.0 (opens in new tab)
- @sveltejs/adapter-node@6.0.0 (opens in new tab)
- @sveltejs/adapter-vercel@7.0.0 (opens in new tab)
- @sveltejs/adapter-netlify@7.0.0 (opens in new tab)
- @sveltejs/adapter-cloudflare@8.0.0 (opens in new tab)
- @sveltejs/adapter-bun@1.0.0 (opens in new tab)
- @sveltejs/adapter-static@4.0.0 (opens in new tab)
- @sveltejs/adapter-auto@8.0.0 (opens in new tab)
- @sveltejs/package@3.0.0 (opens in new tab)
- @sveltejs/enhanced-img@1.0.0 (opens in new tab)
- @sveltejs/kit@3.0.0-next.32 (opens in new tab)
- @sveltejs/kit@3.0.0-next.31 (opens in new tab)
- @sveltejs/adapter-cloudflare@8.0.0-next.8 (opens in new tab)
- What’s new in Svelte: October 2026 (opens in new tab)
- Next.js v16.3.8 patches SSRF in Image Optimization and cache poisoning flaws (opens in new tab)
- Next.js v15.5.27 patches SSG and ISR cache poisoning vulnerabilities (opens in new tab)
- Next.js v16.4.0-canary.53 enables Cache Components by default in create-next-app (opens in new tab)
- Next.js v16.4.0-canary.55 enables turbopackSharedRuntime by default (opens in new tab)
- Next.js v16.4.0-canary.54 fixes draft mode leak and MCP middleware DNS rebinding (opens in new tab)
- Next.js v16.4.0-canary.52 drops unstable_ prefix from navigation() and prefetch() (opens in new tab)
- Next.js v16.4.0-canary.56 enables Turbopack export name mangling by default (opens in new tab)
- Next.js v16.4.0-canary.59 fixes unnecessary Suspense fallback on URL updates (opens in new tab)
- Next.js v16.3.7 fixes hanging strongly consistent read on canceled task (opens in new tab)
- Next.js v16.4.0-canary.60 unifies bundle analyzer delta colors (opens in new tab)
- Next.js v16.4.0-canary.58 bundles Turbopack caching and source map tooling updates (opens in new tab)