A critical remote-code-execution flaw in Next.js's image-rendering library, disclosed on September 30, 2026, was closed across every affected repository in the estate within about two hours of being caught — nineteen pull requests, one per repository, each verified clean before merge.
The advisory is rated critical: a remote-code-execution path through the ImageResponse function in next/og, present in Next.js versions 16.2.0 up to but not including 16.3.6. Every one of the eighteen Next.js applications in the estate was running 16.3.3 or 16.3.5 — squarely inside the vulnerable range — and eight of them call next/og directly.
It surfaced as a red result on the weekly dependency-audit lane, flagged against an unrelated Hub pull request the afternoon after the advisory published. Nobody read the CVE feed and started a fire drill — a routine check that runs every Monday happened to catch this one on a Thursday, because the lane watches dependency versions continuously, not on a schedule tied to when someone remembers to look.
Eight different call sites importing the same vulnerable function isn't eight separate bugs to track down. It's one advisory and a dependency bump, repeated nineteen times.
Nineteen pull requests, one per repository, squash-merged within roughly two hours of each other: next and eslint-config-next moved to 16.3.8 across seventeen standalone repos, plus the monorepo's own dekimuhq.com app and the shared app-starter template in a single PR, plus the dev-dependency in four of the shared-package workspaces that build on Next (with no change to the published peer-dependency range, so no package republish was needed). A couple of repos picked up unrelated fixes riding in the same pass — a low-severity dompurify bump on Hub, and npm audit fix runs on two other apps for an unconnected transitive brace-expansion and moment advisory.
Every one of the nineteen repos was type-check clean and audit-clean at high severity and above before its PR merged — that was the bar, not a best effort. One exception was named rather than hidden: verify.dekimu.com still carries three low-severity findings sitting behind a major-version bump of its opentimestamps dependency, deliberately left out of this pass because that upgrade is its own separate piece of work. The estate's existing auto-deploy-on-merge wiring carried the fix to production without a separate release step on any of the nineteen repos.
This post was drafted by an AI system from Dekimu's public engineering record and published with automated checks, without per-post human editing.
← Back to blog