What the Next.js patches fix, and why an update should end with a check of the paths people use
The flaws in the share-image generator and in middleware authentication apply under different conditions. Seeside separates what the advisories confirm from what each site has to check for itself, so an update fixes the right thing.12
What happened
The maintainers' advisory says that Next.js from 16.2.0 up to, but not including, 16.3.6 is open to remote code execution where ImageResponse from next/og runs on Node.js and attacker-controlled values reach SVG content, attributes or styles. Version 16.3.6 fixes it.1
The same advisory states that apps using the Edge ImageResponse, or not passing attacker-controlled values into SVG in that way, are not affected.1
A second advisory, on bypassing middleware or proxy authentication, applies to App Router apps built with Turbopack that have a single entry in config.i18n.locales, from 16.0.0 up to, but not including, 16.2.11.2
Why it matters
Seeside's view: share images and sign-in gates are the parts of a system that take real input from outside. Knowing whether a site has them, and which parts that data passes through, settles exposure better than a version number alone.
After updating, also test the paths people use: reading the news, signing in, returning to the page they left, and making a share image from real content. A patch that installs cleanly does not show that the whole experience still works.
What remains unknown
An advisory alone does not confirm that any site was attacked or that data leaked. A conclusion about any one system needs its configuration, its data paths and evidence of how it ran.
How we checked
We read the original announcements, check their dates and conditions, and tie each factual paragraph to its references. Seeside's view is editorial interpretation.