{"record":{"id":"162bc8667578226e","repo":"vercel/next.js","slug":"no-safe-next-js-update-is-currently-available","errorCode":null,"errorMessage":"No safe Next.js update is currently available.","messagePattern":"No safe Next\\.js update is currently available\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/next/src/lib/upgrade/prepare-upgrade.ts","lineNumber":549,"sourceCode":"    }\n  }\n\n  for (const major of [...latest.keys()].sort((a, b) => a - b)) {\n    if (major < semver.major(source)) {\n      continue\n    }\n\n    const candidate = latest.get(major)!\n\n    if (\n      semver.gt(candidate.version, source) &&\n      !ranges.some((range) => semver.satisfies(candidate.version, range))\n    ) {\n      return candidate\n    }\n  }\n\n  throw new Error('No safe Next.js update is currently available.')\n}\n","sourceCodeStart":531,"sourceCodeEnd":551,"githubUrl":"https://github.com/vercel/next.js/blob/34433fd12ee8074ea3f47af9f36255c7390d0301/packages/next/src/lib/upgrade/prepare-upgrade.ts#L531-L551","documentation":"When the installed Next.js version is inside a known vulnerable range, selectSecurityTarget searches the latest stable release of each major (>= the installed major) for one that is newer than the installed version AND outside all vulnerable ranges. This error is thrown when no such release exists — every newer candidate release is itself affected by an open advisory, so the tool refuses to pick an unsafe target.","triggerScenarios":"Running `next upgrade` (security path via `selected`) while the installed version matches a vulnerable range and every newer latest-stable major release also satisfies some vulnerable range — e.g. installing a freshly-published, already-advisory-affected release, or an advisory that spans all current majors.","commonSituations":"A zero-day advisory covering the latest Next.js releases; upgrading immediately after a new vulnerable version shipped before a patched release is out; pinning to canary/RC versions that all fall in affected ranges.","solutions":["Wait for the patched Next.js release and re-run `next upgrade`; the tool will then select it automatically.","Check the referenced advisory feeds (the error context lists ADVISORIES/NPM_ADVISORIES URLs) for the fixed version and manually install it with npm/pnpm.","If you believe the advisory does not affect your usage, upgrade manually with an explicit version while consciously accepting the flagged risk.","Upgrade to the newest available major anyway only if you have independently verified the vulnerability does not apply (not recommended for production)."],"exampleFix":"// before\nnpx next upgrade\n// error: No safe Next.js update is currently available.\n// after: wait for / manually pin the patched release\nnpm install next@<patched-version>","handlingStrategy":"fallback","validationCode":"// pre-check whether the installed version is currently flagged\nconst advisories = await (await fetch('https://api.github.com/advisories?ecosystem=npm&affects=next')).json()\nconst affected = advisories.some(a => a.vulnerabilities.some(v =>\n  require('semver').satisfies(require('next/package.json').version, v.vulnerable_version_range)))\nconsole.log(affected ? 'Affected: wait for patched release' : 'Not affected: normal upgrade path')","typeGuard":null,"tryCatchPattern":"try {\n  await upgrade()\n} catch (e) {\n  if (e.message === 'No safe Next.js update is currently available.') {\n    // do NOT force-upgrade; wait for the patched release or review the advisory manually\n  } else throw e\n}","preventionTips":["Don't upgrade the moment a new Next.js version ships during an active security incident; check advisories first.","Subscribe to Next.js security advisories to know when the patched release lands.","Avoid canary/RC versions in production to stay inside well-covered safe ranges."],"tags":["security","upgrade","versioning","semver"],"backgroundTag":"no-safe-version-available","analyzedSha":"34433fd12ee8074ea3f47af9f36255c7390d0301","analyzedAt":"2026-09-20T18:20:20.576Z","contentChangedAt":"2026-09-20T18:20:20.576Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}