Remote code execution in next/og ImageResponse, fixed in 16.3.6.
Same minor line; the exact pin in package.json moves too and the
lockfile follows (next, @next/env, @next/swc-* platform binaries,
sharp optional range ^0.35.4).
Not fixed here (need a direct-dependency major bump or have no fix):
- nodemailer 9.1.1: GHSA-prgh-xp8r-p3m5 / GHSA-v53p-9fqp-m79j fixed only in 10.0.5/10.0.6 (major)
- xlsx 0.20.3: GHSA-4r6h-8v6p-xvw6 / GHSA-5pgg-2g8v-p4x9 have no published fix
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Lockfile-level update of the packages trivy flags on main, all within
their current major:
- next 16.3.1 -> 16.3.3 (CVE-2026-75604, CRITICAL)
- js-yaml 4.3.1 -> 4.3.2 (CVE-2026-84375)
- nodemailer 9.0.5 -> 9.1.1 (GHSA-2x7j-588g-ccc2, GHSA-8m3c-c648-2xjj)
- sharp 0.35.3 -> 0.35.5 (GHSA-rgj7-g3m4-5g8c)
- undici 6.28.0 -> 6.29.0 (CVE-2026-19534)
- brace-expansion -> 1.1.21 / 2.1.7 (CVE-2026-102276, CVE-2026-102278, dev)
- minimatch 9.0.5 -> 9.0.9 (CVE-2026-26996/27903/27904, dev)
next, js-yaml and nodemailer were exact-pinned, so their pins move too.
PINNED_DEPS in the antipattern guard follows nodemailer to 9.1.1; without
it the pinned-dep guard fails.
Remaining: nodemailer GHSA-v53p-9fqp-m79j is only fixed in 10.x (major
bump of a direct dependency, left for a separate reviewed change).
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>