Next.js 16.3.8 security release: does a Sume webhook route change?

Seven Next.js advisories shipped September 30 in 16.3.8 and 15.5.27. None names Route Handlers, so upgrade, then re-run a signed Sume test delivery.

4 min readSume
All posts

Upgrade, but expect no code change in a Sume webhook route. The seven advisories in the September 30 release are about image optimization, caching, metadata routes, Draft Mode and the dev server, and the release notes do not mention Route Handlers or webhooks.

Next.js facts are from the vendor's security release post; Sume facts from Verifying webhooks and Job webhooks, read 2026-10-01.

What shipped?

The fixes are in v16.3.8 and v15.5.27. The post lists seven advisories. It marks the Image Optimization SSRF as High (CVE-2026-94483, not applicable without images.remotePatterns), and the dev-server MCP disclosure as Low (CVE-2026-94486).

September 2026 Next.js advisories from the vendor post, read 2026-10-01
AreaIdentifierNote from the post
Image Optimization SSRFCVE-2026-94483High; unaffected without images.remotePatterns
Self-hosted Pages Router SSG/ISR cache poisoningCVE-2026-94543Not Vercel
SSG/ISR cache poisoning with root catch-allCVE-2026-94484Page cache
Metadata image routes dynamicParams bypassCVE-2026-94485webpack only
Nested use cache root-param leakSee the vendor postCache
Draft Mode leak via pending use cache fillCVE-2026-94544Cache
Dev-server MCP endpoint disclosureCVE-2026-94486Low; next dev only

Is a webhook Route Handler in scope?

The post names none of the seven as a Route Handler issue. A Sume receiver is a POST that reads the raw body and returns a 2xx, so none of the listed areas describes it. I am not claiming it is unaffected beyond that: the page does not say.

What should you re-check after upgrading?

Verify behavior, not versions. Send a test delivery with POST /v1/webhooks/test-deliveries and confirm the route still returns a 2xx and rejects a bad signature.

Keep the handler on the documented pattern: read await request.text() first, await verifyWebhook, and refuse an empty secret.

import { verifyWebhook } from "@sume-com/sdk";

const seen = new Set<string>(); // use a durable store in production

export async function POST(request: Request) {
  const secret = process.env.SUME_COM_WEBHOOK_SIGNING_SECRET ?? "";
  if (!secret) return new Response("not configured", { status: 500 });

  const body = await request.text(); // raw, before any JSON.parse
  const ok = await verifyWebhook({ body, headers: request.headers, secret });
  if (!ok) return new Response("bad signature", { status: 401 });

  const event = JSON.parse(body);
  if (event.job_id && seen.has(event.job_id)) return new Response(null, { status: 204 });
  if (event.job_id) seen.add(event.job_id);
  return new Response(null, { status: 204 });
}

What about the image SSRF fix?

That one has its own walkthrough for media URLs: remotePatterns and media.sume.com.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume