Telemetry delivery now works on Node.js 24, the deprecated React.FormEvent type is replaced with SubmitEvent, and next is bumped in upgrade eval fixtures for CVE-2026-94483. Plus quieter Turbopack and filesystem watcher warnings and assorted CI and docs fixes.
Next.js
npx @buildinternet/releases get next-jscreate-next-app now writes an agent feedback block to AGENTS.md when enabled and scaffolds new projects with ESLint 10, alongside a new turbo-trace-size CLI and a no-memory flag for NEXT_TURBOPACK_TRACING. Turbopack also batches EsmBinding codegen, fixes unused dependencies and trace-size test fallout from MemorySample's active_worker_threads, and the toolchain bumps to swc v81 and rustc nightly-2026-10-04.
Check out the 16.4 announcement post to get an overview of the changes.
Core Changes
- Show compiler plugin warning in more situations: #75682
- fix(scripts): correct typo in rm.mjs error message: #87015
- docs: improve clarity…
Turbopack now reports next/font/google font file fetch failures instead of "Module not found", and font data was updated with a fix for the no-subsets font fixture. The release also adds tracing changes for blocking spans, global trace concurrency, and Tokio worker thread memory samples, plus a vendored @mswjs/interceptors bump.
Turbo-tasks snapshot handling changes: pending bits are captured under exclusion in an experiment, tasks are copied on first modification during a snapshot, persisting is disabled after a failed snapshot, and copy-on-write snapshots are bincode-encoded instead of cloned. Custom-route metadata is now kept outside configuration.
Stabilization of forbidden() and unauthorized() is reverted, and configured output directories are now preserved during static export. Also documents next analyze export in the package bundling guide and renames the skill to next-bundle-optimizer.
Static route error guidance is improved, and agent upgrade prompts now show choices while keeping dev and build running. Also includes Turbopack invalidator fixes, turbo-tasks-backend changes around GC-collected tasks, and new Bundle Analyzer Agent Skill features.
The forbidden() and unauthorized() APIs are now stable, and eslint-config-next adds support for ESLint 10. Also reverts the ESM exports protocol-burden optimization, plus Turbopack path caching and 'use cache' build-time param dependency work.
The bundle analyzer now uses unified colors for deltas.
Client params no longer suspend on shallow URL updates, preventing an unnecessary Suspense fallback from being triggered. Also adds a React Compiler memoization preservation option and allocation and memory data to the trace-server MCP protocol.
This canary shifts the Turbopack module cache into a Map, switches the disk file system map to a FrozenMap, and adds a bundle analyzer route summary. Also upgrades React to 278794d7-20261002, warns when Partial Prefetching is unconfigured, and updates the MCP guide for next-devtools-mcp 0.4.
Turbopack export name mangling is now enabled by default for builds, and a new unstable parameter matching API is available. Other changes include preferring the declared package manager during upgrades, allowing React and ESLint upgrades to be skipped, and passing App Page HMR state through a dev render context.
Turbopack now enables experimental.turbopackSharedRuntime by default. Also fixed repeated tag revalidation propagation from after() and stabilized ensureStatic.
Draft mode no longer leaks through cross-request "use cache" deduplication, and an MCP middleware DNS rebinding issue is fixed. Also scopes response cache keys to their source route, matches Next data paths case-sensitively, pins DNS resolution when fetching external images, and keeps ISR cache lifetimes across instances and restarts.
Patches a high-severity server-side request forgery in Image Optimization and five medium-severity issues including cache poisoning of SSG and ISR pages, cross-user content substitution, Draft Mode content leaking into persisted pages via a pending use cache fill, and a cache leak across root param values in nested use cache functions. Also fixes a low-severity information disclosure in the development server's Model Context Protocol endpoint.
Fixes three medium-severity advisories: cache poisoning of SSG and ISR pages in self-hosted apps, cache poisoning in SSG/ISR rendering leading to cross-user content substitution and persistent denial of service, and information disclosure in App Router metadata image routes via dynamicParams bypass.
create-next-app now enables Cache Components by default, a default-behavior change for new projects scaffolded with the canary. Also fixes HTTP status codes being dropped during prerendering and a bundle analyzer route selector bug.
A backport release fixing a turbo-tasks-backend issue where a strongly consistent read would hang on a canceled task. The release contains only this fix and does not include pending canary features or changes.
