Next.js 16.3.8 security release: does a Sume webhook route change?
Seven Next.js advisories shipped September 30 in 16.3.8 and 15.5.27. None names Route Handlers, so upgrade, then re-run a signed Sume test delivery.

Upgrade, but expect no code change in a Sume webhook route. The seven advisories in the September 30 release are about image optimization, caching, metadata routes, Draft Mode and the dev server, and the release notes do not mention Route Handlers or webhooks.
Next.js facts are from the vendor's security release post; Sume facts from Verifying webhooks and Job webhooks, read 2026-10-01.
What shipped?
The fixes are in v16.3.8 and v15.5.27. The post lists seven advisories. It marks the Image Optimization SSRF as High (CVE-2026-94483, not applicable without images.remotePatterns), and the dev-server MCP disclosure as Low (CVE-2026-94486).
| Area | Identifier | Note from the post |
|---|---|---|
| Image Optimization SSRF | CVE-2026-94483 | High; unaffected without images.remotePatterns |
| Self-hosted Pages Router SSG/ISR cache poisoning | CVE-2026-94543 | Not Vercel |
| SSG/ISR cache poisoning with root catch-all | CVE-2026-94484 | Page cache |
Metadata image routes dynamicParams bypass | CVE-2026-94485 | webpack only |
Nested use cache root-param leak | See the vendor post | Cache |
Draft Mode leak via pending use cache fill | CVE-2026-94544 | Cache |
| Dev-server MCP endpoint disclosure | CVE-2026-94486 | Low; next dev only |
Is a webhook Route Handler in scope?
The post names none of the seven as a Route Handler issue. A Sume receiver is a POST that reads the raw body and returns a 2xx, so none of the listed areas describes it. I am not claiming it is unaffected beyond that: the page does not say.
What should you re-check after upgrading?
Verify behavior, not versions. Send a test delivery with POST /v1/webhooks/test-deliveries and confirm the route still returns a 2xx and rejects a bad signature.
Keep the handler on the documented pattern: read await request.text() first, await verifyWebhook, and refuse an empty secret.
import { verifyWebhook } from "@sume-com/sdk";
const seen = new Set<string>(); // use a durable store in production
export async function POST(request: Request) {
const secret = process.env.SUME_COM_WEBHOOK_SIGNING_SECRET ?? "";
if (!secret) return new Response("not configured", { status: 500 });
const body = await request.text(); // raw, before any JSON.parse
const ok = await verifyWebhook({ body, headers: request.headers, secret });
if (!ok) return new Response("bad signature", { status: 401 });
const event = JSON.parse(body);
if (event.job_id && seen.has(event.job_id)) return new Response(null, { status: 204 });
if (event.job_id) seen.add(event.job_id);
return new Response(null, { status: 204 });
}What about the image SSRF fix?
That one has its own walkthrough for media URLs: remotePatterns and media.sume.com.
Sources
Related posts
More in Developers
- Revised NO FAKES Act: counter-notice and what it means for APIs
The revised NO FAKES Act adds counter-notice, a research exemption and streaming-music fixes. A plain summary read against avatar, face-swap and music routes.
- Notion 429/529 retry_after in the body vs Sume retry-after header
Notion now puts additional_data.retry_after in 429/529 bodies. Sume sends a retry-after header on rate_limited. One small helper can read both.
- Notion MCP 20 calls per 10 seconds: poll Sume jobs less
Notion MCP allows 20 search and 20 data source query calls per connection every 10 seconds. Use a Sume webhook so job polling does not compete for them.
- OpenAI Agents API durable sessions and Sume job ids
A durable OpenAI Agents API session continues across turns; a Sume render is a separate job. Keep the job id in the session and re-read it, never re-create.
Written by Sume