Eight days after the next/og remote code execution fix, Vercel shipped another Next.js security release. This one carries seven advisories. One of them is an information disclosure in the development server’s Model Context Protocol endpoint, which is a sentence that would not have parsed two years ago and now just sits in a changelog between an SSRF and a cache poisoning bug.
Here is what mattered in React and React Native for September 28 to October 4, 2026.
News
Next.js 16.3.8: seven advisories, one of them in the dev server’s MCP endpoint
Next.js 16.3.8 and 15.5.27 landed on September 30. The high severity one is Server-Side Request Forgery in Image Optimization, listed for the 16.x release only. Then a run of medium ones: an information disclosure in App Router metadata image routes via a dynamicParams bypass, two separate cache poisoning bugs in SSG and ISR on self-hosted deployments (one of them can serve one user’s content to another), Draft Mode content leaking through a pending use cache fill, and a cache leak across root param values in nested use cache functions. The low one is the dev server MCP disclosure. 16.3.7 the day before was a single Turbopack backport for a read that could hang on a cancelled task.
My take: the pattern of the last two weeks is that the risky surface in Next.js is no longer the router, it is everything that generates or caches on the server on your behalf. Image optimization, OG images, ISR, use cache. Those are the features you turn on in an afternoon and stop thinking about. If you self-host, the two cache poisoning advisories are the ones to read properly, because Vercel’s own platform is not where they bite. And if you run next dev on a shared network with an agent attached, upgrade before you find out what it was disclosing.
Expo SDK 58 is on npm as 58.0.x, still behind the next tag
[email protected] was published on September 29 and reached 58.0.3 by Saturday, all under the next dist-tag. latest is still 57.0.26, which also shipped on the 29th. That is consistent with what the SDK 58 beta post promised: the SDK runs on the React Native 0.88 release candidate, and the stable SDK follows the stable React Native release. The bundled module list for 58.0.3 pins react-native to 0.88.0-rc.3, Reanimated to 4.7.0 and react-native-webview to 14.0.1. The 58.0.3 notes switch Expo to the TextDecoder that Hermes now provides, which adds UTF-16, Latin-1 and Windows-1252, and warns that custom JS runtimes must provide TextDecoder before Expo initializes.
Two smaller packages from the same Saturday batch are worth knowing about. expo-notifications 58.1.0 adds an enableRemoteNotifications config plugin option, so apps that only schedule local notifications can finally stop shipping the APNs entitlement. And expo-modules-cli 0.2.0 is a new package whose generate-types command reads your Swift module and writes the TypeScript for the API it exports. Anyone who has kept a hand-written .d.ts in sync with a native module knows how much of a relief that is going to be.
EAS CLI can now record your app’s network traffic
EAS CLI 24.10.0 on October 2 adds --network-capture to eas simulator, recording HTTP and HTTPS traffic from the app on the device, with --network-capture-field to also keep headers, query values or bodies. It landed three hours after 24.9.0, which had the bigger list: eas update --upload-source-maps so stack traces from an OTA update can be symbolicated (with sourcesContent stripped first), the embedded bundle uploaded after build by default on SDK 58, --force-end-active-rollout across the update commands, and Android local egress for cloud emulators.
The source maps change is the one I would turn on today. An OTA update that crashes in production with a minified stack trace is the worst hour of a release week, and until now the fix was a side script nobody maintained.
Releases
React Native 0.88.0-rc.3
0.88.0-rc.3 shipped September 28 with a short, practical list. Hermes moves to 260318099.0.4, which avoids a quadratic reserve() during lazy compilation. On Android, androidx.collection goes to 1.4.4 to fix view registry entries getting lost in the mounting manager. On iOS, SwiftPM autolinking stops recreating library package roots on every sync, which had been breaking Xcode builds for libraries that ship their own Package.swift. No new features, which is exactly what rc.3 should look like. Expo is waiting on this one, so the stable is the thing to watch next week.
Reanimated 4.7.1 cleans up after the layout engine swap
Two weeks ago 4.7.0 made the new layout animations engine the default. 4.7.1 on October 2 is the stability pass: synchronously updated props no longer snap back to old values when a sibling’s zIndex change moves a view, several Android crashes are fixed (unknown sensor type in useAnimatedSensor, nested Text props read as view props, a removed native stack screen holding a nested stack with header buttons on react-native-screens older than 4.27), and withTiming no longer extrapolates its easing when the first frame’s timestamp is earlier than the animation’s start. That last one is a fun bug. A bezier easing with x1 = 0 sends the solver just outside its domain, and for one frame the animated value lands orders of magnitude out of range. If you have ever seen a single frame flash at the wrong size and blamed your own code, it may not have been your code.
Skia 2.13.1 and 2.14.0
react-native-skia 2.14.0 on October 1 removes the mutable SkPath API along with its deprecation warnings, and the declarative renderer no longer needs the garbage collector to clean up after it. 2.13.1 on September 29 made interpolatePaths fail clearly on degenerate inputs and improved memory pressure reporting. If you mutate paths in place, this is the release that breaks you, so check before bumping. Our Skia guide already uses the immutable builders.
Everything else that moved
React Navigation 7.x got a minor train on September 29: tabBarRepeatedPressBehavior on tabs (what happens when the user taps the tab they are already on, which is the most requested small thing in every tab bar I have built), removal prevention that works when navigation was suspended, and root state built only when something is listening. The v8 alphas moved again the same day. FlashList 2.3.3 fixes blank rows during fast scrolling when drawDistance is small. Vite 8.3.2 is a bug fix sweep, including a file watcher error that no longer crashes the dev server. TanStack Query 5.104.1 and TanStack Router 1.170.41 shipped patch releases, the router one reusing link href classification across location updates. Storybook 10.6.1 supports Vitest 5 browser tests. Next.js 16.4 canaries 52 to 60 kept coming. Node and Bun were quiet all week.
Worth reading
Live Activities, both halves
Expo’s blog ran Live Activities with Expo, end to end on October 1. Most Live Activity tutorials stop at the widget. This one goes through per-activity push tokens, push-to-start, the APNs request and the gotchas on the server side, using a receipt processing flow that takes a few seconds to a minute. That is a better example than food delivery, because it is the shape most apps actually have.
Agentic CI, the other half of last week’s story
Last Monday we covered Expo’s agent that turns a bug report into a pull request. Agentic CI for Expo apps with TesterArmy (September 29, guest post) is about the pull request that has not merged yet: a pipeline that picks what to build and what to test per change instead of running the same list. Read it with the right amount of salt, it is a vendor post. The problem it names is real though. Agents make the PR cheap and leave the review exactly as expensive as it was.
The threads
The top of r/reactnative this week reads like a mood board. Does React Native make sense in 2026? and Another RN to Native story are still Shopify aftershocks, three weeks on. Right next to them, someone open sourced simfleet to run many React Native worktrees in parallel on slimmed simulators, and someone else wrote a tile-based PDF viewer because the existing ones fall over on engineering drawings. People who think the platform is dying do not usually build tooling for running six copies of it at once. And why would anyone choose expo-maps over react-native-maps is a fair question that our maps guide tries to answer.
Both official blogs were quiet again: nothing on react.dev since 19.3 on September 9, nothing on reactnative.dev since August. On this site, a practical react-native-webview guide goes up Wednesday and a dropdowns and pickers comparison on Friday. If I missed something you shipped, tell me in the comments and it goes in next Monday.