On August 25, we plan to publish Next.js 16.3.3 and 15.5.24, moving the security release forward from the previously announced August 26 date.
The release is now expected to address two critical severity vulnerabilities rather than one. The newly identified issue prompted us to move the release forward. We are addressing both vulnerabilities in the same release so users only need to upgrade once.
Later today, we will publish the patched versions alongside full advisory details, including impact, affected versions, and upgrade instructions. We recommend upgrading as soon as the release is available.
Our security program
We work with security researchers to secure Next.js and other open source frameworks through Vercel's Open Source Bug Bounty. Anyone interested in contributing to the security of eligible frameworks is encouraged to participate there.
Any questions or concerns regarding our security programs or vulnerability management can be sent to security@vercel.com.











