---
collection: frontend-frameworks
collection_name: Frontend Frameworks
week_start: 2026-09-28
title: Next.js patches critical SSRF and cache flaws as SvelteKit 3 lands
release_count: 29
generated: 2026-10-05
canonical: https://releases.sh/collections/frontend-frameworks/digest/2026-09-28
---

# Next.js patches critical SSRF and cache flaws as SvelteKit 3 lands

Security took center stage this week as Next.js patched a high-severity server-side request forgery in Image Optimization alongside a range of cache-poisoning fixes across two release lines, while SvelteKit shipped its long-awaited 3.0 major with a coordinated wave of rewritten adapters.

### Next.js closes a high-severity SSRF and a cluster of cache flaws

Vercel's framework had an unusually heavy security week, and the fixes spanned both the current and previous major lines. The headline is a [high-severity server-side request forgery in Image Optimization](https://github.com/vercel/next.js/releases/tag/v16.3.8), patched together with five medium-severity issues: cache poisoning of SSG and ISR pages, cross-user content substitution, Draft Mode content leaking into persisted pages through a pending `use cache` fill, and a cache leak across root param values in nested `use cache` functions. A low-severity information-disclosure bug in the development server's Model Context Protocol endpoint was fixed alongside them.

Projects still on the older line aren't stranded — the same fixes, minus the SSRF, arrived as [cache-poisoning patches for SSG and ISR on the previous major](https://github.com/vercel/next.js/releases/tag/v15.5.27), covering the metadata image-route disclosure and the persistent denial-of-service variant of the cache bug. If you self-host, this is the week to take both.

Underneath the security work, the canary line kept moving on Turbopack and caching. New projects scaffolded from the canary now get [Cache Components enabled by default in create-next-app](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.53), and the shared Turbopack runtime is [enabled by default with stabilized `ensureStatic`](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.55). Elsewhere: [Draft Mode no longer leaks through cross-request `use cache` deduplication](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.54), with response cache keys now scoped to their source route and DNS pinned when fetching external images; [navigation() and prefetch() lost their `unstable_` prefix](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.52), a breaking rename worth grepping for; [export name mangling is on by default for Turbopack builds](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.56) alongside a new unstable parameter-matching API; and [client params no longer suspend on shallow URL updates](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.59), killing an unnecessary Suspense fallback. A [strongly consistent read that could hang on a canceled task](https://github.com/vercel/next.js/releases/tag/v16.3.7) was backported to the stable line, and the bundle analyzer picked up [unified delta colors](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.60) and a [route summary over a reworked module cache](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.58).

### SvelteKit 3 arrives, with every adapter rewritten

The week's other big story: [SvelteKit 3 is here](https://svelte.dev/blog/sveltekit-3-is-here), the framework's first major in years. The theme is polish and type safety rather than reinvention, with an `sv migrate` command smoothing the upgrade. Breaking changes include [remote function types moving to `$app/server`, synchronous `getRequest`/`setResponse`, and a TypeScript 6 minimum](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0), plus the removal of the `experimental.handleRenderingErrors` flag.

The release pulled a coordinated version bump across the whole adapter ecosystem, most of which now [requires SvelteKit 3 and populates env vars before `instrumentation.server.js` is evaluated](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-node%406.0.0). Several adapters moved to rolldown for bundling, including [Vercel's edge bundling on an es2022 target](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-vercel%407.0.0) and [Netlify's output conforming to the stable Frameworks API](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-netlify%407.0.0). The [Cloudflare adapter raised its Wrangler floor](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-cloudflare%408.0.0), the [Bun adapter gained a native static-serving mode on Bun 1.4](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-bun%401.0.0), the [static adapter started matching adapter-vercel's prerendered redirect handling](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-static%404.0.0), and [adapter-auto added zero-config deploys for Render](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-auto%408.0.0). Tooling kept pace: [`@sveltejs/package` now warns on server-only files used without a server-only import](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/package%403.0.0), and [`@sveltejs/enhanced-img` moved to Vite 8 and `vite-plugin-svelte` 7](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/enhanced-img%401.0.0). In the run-up, the team shipped a stream of fixes across [one pre-release that closed an enhanced-form cross-origin navigation and escaped cache-control headers in prerendered HTML](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.32), [another that fixed `scrollRestoration` surviving back/forward cache restores and clearing `navigating` on aborted popstate](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.31), and a [Cloudflare adapter patch disposing the platform proxy on server close](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-cloudflare%408.0.0-next.8). The monthly roundup captures [the final changes before 3.0 and `sv` hitting 1.0](https://svelte.dev/blog/whats-new-in-svelte-october-2026).

### Expo sharpens simulator and update workflows

EAS CLI's two releases this week both target the inner loop. [`eas simulator` can now record HTTP(S) traffic from apps on the device](https://github.com/expo/eas-cli/releases/tag/v24.10.0), with a companion flag for keeping headers, query values, and bodies — a genuine debugging upgrade for network issues that only reproduce on-device. Separately, [`eas update` gained source-map uploads for stack-trace symbolication and a force-end-rollout flag](https://github.com/expo/eas-cli/releases/tag/v24.9.0), with embedded bundle uploads after build now on by default for SDK 58+ projects and App Store Connect token reuse fixed.

## Releases covered

### Expo

- [EAS CLI v24.10.0 adds network capture to eas simulator](https://github.com/expo/eas-cli/releases/tag/v24.10.0)
- [EAS CLI v24.9.0 adds --upload-source-maps and force-end rollout flag](https://github.com/expo/eas-cli/releases/tag/v24.9.0)

### Svelte

- [SvelteKit 3 is here](https://svelte.dev/blog/sveltekit-3-is-here)
- [@sveltejs/kit@3.0.0](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0)
- [@sveltejs/adapter-node@6.0.0](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-node%406.0.0)
- [@sveltejs/adapter-vercel@7.0.0](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-vercel%407.0.0)
- [@sveltejs/adapter-netlify@7.0.0](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-netlify%407.0.0)
- [@sveltejs/adapter-cloudflare@8.0.0](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-cloudflare%408.0.0)
- [@sveltejs/adapter-bun@1.0.0](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-bun%401.0.0)
- [@sveltejs/adapter-static@4.0.0](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-static%404.0.0)
- [@sveltejs/adapter-auto@8.0.0](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-auto%408.0.0)
- [@sveltejs/package@3.0.0](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/package%403.0.0)
- [@sveltejs/enhanced-img@1.0.0](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/enhanced-img%401.0.0)
- [@sveltejs/kit@3.0.0-next.32](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.32)
- [@sveltejs/kit@3.0.0-next.31](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.31)
- [@sveltejs/adapter-cloudflare@8.0.0-next.8](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-cloudflare%408.0.0-next.8)
- [What’s new in Svelte: October 2026](https://svelte.dev/blog/whats-new-in-svelte-october-2026)

### Vercel

- [Next.js v16.3.8 patches SSRF in Image Optimization and cache poisoning flaws](https://github.com/vercel/next.js/releases/tag/v16.3.8)
- [Next.js v15.5.27 patches SSG and ISR cache poisoning vulnerabilities](https://github.com/vercel/next.js/releases/tag/v15.5.27)
- [Next.js v16.4.0-canary.53 enables Cache Components by default in create-next-app](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.53)
- [Next.js v16.4.0-canary.55 enables turbopackSharedRuntime by default](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.55)
- [Next.js v16.4.0-canary.54 fixes draft mode leak and MCP middleware DNS rebinding](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.54)
- [Next.js v16.4.0-canary.52 drops unstable_ prefix from navigation() and prefetch()](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.52)
- [Next.js v16.4.0-canary.56 enables Turbopack export name mangling by default](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.56)
- [Next.js v16.4.0-canary.59 fixes unnecessary Suspense fallback on URL updates](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.59)
- [Next.js v16.3.7 fixes hanging strongly consistent read on canceled task](https://github.com/vercel/next.js/releases/tag/v16.3.7)
- [Next.js v16.4.0-canary.60 unifies bundle analyzer delta colors](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.60)
- [Next.js v16.4.0-canary.58 bundles Turbopack caching and source map tooling updates](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.58)
