Releases Index

BetaWeekly digests are a beta — we're trying something new. Feedback welcome.

Next.js patches critical SSRF and cache flaws as SvelteKit 3 lands

September 28 – October 4, 2026

VercelSvelteExpo
Vercel, Svelte, Expo

Security took center stage this week as Next.js patched a high-severity server-side request forgery in Image Optimization alongside a range of cache-poisoning fixes across two release lines, while SvelteKit shipped its long-awaited 3.0 major with a coordinated wave of rewritten adapters.

Next.js closes a high-severity SSRF and a cluster of cache flaws

Vercel's framework had an unusually heavy security week, and the fixes spanned both the current and previous major lines. The headline is a high-severity server-side request forgery in Image Optimization, patched together with five medium-severity issues: cache poisoning of SSG and ISR pages, cross-user content substitution, Draft Mode content leaking into persisted pages through a pending use cache fill, and a cache leak across root param values in nested use cache functions. A low-severity information-disclosure bug in the development server's Model Context Protocol endpoint was fixed alongside them.

Projects still on the older line aren't stranded — the same fixes, minus the SSRF, arrived as cache-poisoning patches for SSG and ISR on the previous major, covering the metadata image-route disclosure and the persistent denial-of-service variant of the cache bug. If you self-host, this is the week to take both.

Underneath the security work, the canary line kept moving on Turbopack and caching. New projects scaffolded from the canary now get Cache Components enabled by default in create-next-app, and the shared Turbopack runtime is enabled by default with stabilized ensureStatic. Elsewhere: Draft Mode no longer leaks through cross-request use cache deduplication, with response cache keys now scoped to their source route and DNS pinned when fetching external images; navigation() and prefetch() lost their unstable_ prefix, a breaking rename worth grepping for; export name mangling is on by default for Turbopack builds alongside a new unstable parameter-matching API; and client params no longer suspend on shallow URL updates, killing an unnecessary Suspense fallback. A strongly consistent read that could hang on a canceled task was backported to the stable line, and the bundle analyzer picked up unified delta colors and a route summary over a reworked module cache.

SvelteKit 3 arrives, with every adapter rewritten

The week's other big story: SvelteKit 3 is here, the framework's first major in years. The theme is polish and type safety rather than reinvention, with an sv migrate command smoothing the upgrade. Breaking changes include remote function types moving to $app/server, synchronous getRequest/setResponse, and a TypeScript 6 minimum, plus the removal of the experimental.handleRenderingErrors flag.

The release pulled a coordinated version bump across the whole adapter ecosystem, most of which now requires SvelteKit 3 and populates env vars before instrumentation.server.js is evaluated. Several adapters moved to rolldown for bundling, including Vercel's edge bundling on an es2022 target and Netlify's output conforming to the stable Frameworks API. The Cloudflare adapter raised its Wrangler floor, the Bun adapter gained a native static-serving mode on Bun 1.4, the static adapter started matching adapter-vercel's prerendered redirect handling, and adapter-auto added zero-config deploys for Render. Tooling kept pace: @sveltejs/package now warns on server-only files used without a server-only import, and @sveltejs/enhanced-img moved to Vite 8 and vite-plugin-svelte 7. In the run-up, the team shipped a stream of fixes across one pre-release that closed an enhanced-form cross-origin navigation and escaped cache-control headers in prerendered HTML, another that fixed scrollRestoration surviving back/forward cache restores and clearing navigating on aborted popstate, and a Cloudflare adapter patch disposing the platform proxy on server close. The monthly roundup captures the final changes before 3.0 and sv hitting 1.0.

Expo sharpens simulator and update workflows

EAS CLI's two releases this week both target the inner loop. eas simulator can now record HTTP(S) traffic from apps on the device, with a companion flag for keeping headers, query values, and bodies — a genuine debugging upgrade for network issues that only reproduce on-device. Separately, eas update gained source-map uploads for stack-trace symbolication and a force-end-rollout flag, with embedded bundle uploads after build now on by default for SDK 58+ projects and App Store Connect token reuse fixed.

AI-generated digests may contain mistakes.
Releases covered28
Vercel