Traceary

Catalog / Frontend

Next.js changelog

React framework that handles routing, rendering and build output for production sites.

Latest
16.3.3
Shipped
25 Aug 2026yesterday
Collected
30 releasesback to 4 Feb 2026
Source
vercel/next.js
Project
nextjs.org
Feed
RSS

Read today, the first day on record. Collection status

Version history

16.x18 releases
16.3.3

This release contains security fixes for the following advisories: Critical: Unauthenticated Remote Code Execution on windows-hosted servers Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

securityfixed
16.3.2

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes [backport] Scope app-entry export validation to files inside the app directory (#97357) [backport] Fix catch-all index p

fixed
16.3.1

[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by @lukesandberg in https://github.com/vercel/next.js/pull/96653 [16.x] [turbopack] Add turbopack_ecmascript and turbopack_wasm's embeded FS to internal_assets_co

addedchanged
16.3.0

Core Changes Update vendored lodash to 4.17.23 to fix CVE-2025-13465: #91558 Fix invalid HTML response for route-level RSC requests in deployment adapter: #91541 Normalize encoded dynamic placeholders in app routes: #91603 Fix(pages-router)

securityaddedfixed
16.2.12

Backport/docs fixes 16.2 - July round by @icyJoseph in https://github.com/vercel/next.js/pull/96031 [Backport] Fixes to support TypeScript 7 by @lukesandberg in https://github.com/vercel/next.js/pull/95831

fixedchanged
16.2.11

This release contains security fixes for the following advisories: High: Denial of Service in App Router using Server Actions Middleware / Proxy bypass in App Router applications using Turbopack and single locale Server-Side Request Forgery

securityfixed
16.2.10

Contains no changes except publishing @next/swc-wasm-web which was accidentally not published since 16.2.4.

16.2.9

Empty release to ensure next@latest points at a stable release. Next.js only allows publishing with Trusted Publishing enabled. In order to fix NPM dist-tags, we have to release a new version. Updating dist-tags is not possible with Trusted

added
16.2.8

Release with no changes in an attempt to fix next@latest pointing at a prerelease version.

16.2.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes Backport documentation fixes for v16.2 (#93804) [backport] Patch playwright-core to resolve _finishedPromise on requestF

addedfixed
16.2.6

[!NOTE] This release contains security fixes and backported bug fixes. It does not include all pending features/changes on canary. Security Fixes The following advisories have been addressed: High: GHSA-8h8q-6873-q5fj: Denial of Service wit

securityfixed
16.2.5

[!NOTE] This release contains security fixes and backported bug fixes. It does not include all pending features/changes on canary. Security Fixes The following advisories have been addressed: High: GHSA-8h8q-6873-q5fj: Denial of Service wit

securityfixed
16.2.4

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes chore: Bump reqwest to 0.13.2 (Fixes Google Fonts with Turbopack for Windows on ARM64) (#92713) Turbopack: fix filesyste

fixed
16.2.3

[!NOTE] This release is backporting security and bug fixes. For more information about the fixed security vulnerability, please see https://vercel.com/changelog/summary-of-cve-2026-23869. The release does not include all pending features/ch

securityfixed
16.2.2

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes backport: Move expanded adapters docs to API reference (#92115) (#92129) Backport: TypeScript v6 deprecations for baseUr

fixed
16.2.1

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes docs: post release amends (#91715) docs: fix broken Activity Patterns demo link in preserving UI state guide (#91698) Fi

fixed
16.2.0

[!TIP]Check out our Next v16.2 Blog Post to learn more about this release. Core Changes Upgrade React from f93b9fd4-20251217 to 65eec428-20251218: #87323 Turbopack: Create junction points instead of symlinks on Windows: #87606 Turbopack: Sy

securityaddedfixed
16.1.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes [Cache Components] Prevent streaming fetch calls from hanging in dev (#89194) Apply server actions transform to node_mod

securityaddedfixed
15.x12 releases
15.5.24

This release contains security fixes for the following advisories: Critical: Unauthenticated Remote Code Execution on windows-hosted servers Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

securityfixed
15.5.23

[15.x] Port ReplyServer traversal guards to FlightClient @eps1lon in https://github.com/vercel/next.js/pull/96405

changed
15.5.22

[15.5] Reject TypeScript >= 7.0 with an actionable error by @lukesandberg in https://github.com/vercel/next.js/pull/96110

changed
15.5.21

This release contains security fixes for the following advisories: High: Denial of Service in App Router using Server Actions Middleware / Proxy bypass in App Router applications using Turbopack and single locale Server-Side Request Forgery

securityfixed
15.5.20

Contains no changes except publishing @next/swc-wasm-web which was accidentally not published since 15.5.15.

15.5.19

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes [15.5.x] Don't drop FormData entries (#94244) Other [15.5.x] Fix CI (#94281) Credits Huge thanks to @eps1lon for helping

fixed
15.5.18

This release contains security fixes for the following advisories: High: GHSA-8h8q-6873-q5fj: Denial of Service with Server Components GHSA-267c-6grr-h53f: Middleware / Proxy bypass in App Router applications via segment-prefetch routes GHS

securityfixed
15.5.16

This release contains security fixes for the following advisories: High: GHSA-8h8q-6873-q5fj: Denial of Service with Server Components GHSA-267c-6grr-h53f: Middleware / Proxy bypass in App Router applications via segment-prefetch routes GHS

securityfixed
15.5.15

Please refer the following changelogs for more information about this security release: https://vercel.com/changelog/summary-of-cve-2026-23869

security
15.5.14

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes feat(next/image): add lru disk cache and images.maximumDiskCacheSize (#91660) Fix(pages-router): restore Content-Length

addedfixed
15.5.13

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. Core Changes fix: patch http-proxy to prevent request smuggling in rewrites (See: CVE-2026-29057) Credits Huge thanks to @ztanner for

securityfixed
15.5.12

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary. fix unlock in publish-native This is a re-release of v15.5.11 applying the turbopack changes.

fixed