vercel/next.js · error · Error

No safe Next.js update is currently available.

Error message

No safe Next.js update is currently available.

What it means

When the installed Next.js version is inside a known vulnerable range, selectSecurityTarget searches the latest stable release of each major (>= the installed major) for one that is newer than the installed version AND outside all vulnerable ranges. This error is thrown when no such release exists — every newer candidate release is itself affected by an open advisory, so the tool refuses to pick an unsafe target.

Solutions

  1. Wait for the patched Next.js release and re-run `next upgrade`; the tool will then select it automatically.
  2. Check the referenced advisory feeds (the error context lists ADVISORIES/NPM_ADVISORIES URLs) for the fixed version and manually install it with npm/pnpm.
  3. If you believe the advisory does not affect your usage, upgrade manually with an explicit version while consciously accepting the flagged risk.
  4. Upgrade to the newest available major anyway only if you have independently verified the vulnerability does not apply (not recommended for production).

Example fix

// before
npx next upgrade
// error: No safe Next.js update is currently available.
// after: wait for / manually pin the patched release
npm install next@<patched-version>
Defensive patterns

Strategy: fallback

Validate before calling

// pre-check whether the installed version is currently flagged
const advisories = await (await fetch('https://api.github.com/advisories?ecosystem=npm&affects=next')).json()
const affected = advisories.some(a => a.vulnerabilities.some(v =>
  require('semver').satisfies(require('next/package.json').version, v.vulnerable_version_range)))
console.log(affected ? 'Affected: wait for patched release' : 'Not affected: normal upgrade path')

Try / catch

try {
  await upgrade()
} catch (e) {
  if (e.message === 'No safe Next.js update is currently available.') {
    // do NOT force-upgrade; wait for the patched release or review the advisory manually
  } else throw e
}

Prevention

When it happens

Trigger: Running `next upgrade` (security path via `selected`) while the installed version matches a vulnerable range and every newer latest-stable major release also satisfies some vulnerable range — e.g. installing a freshly-published, already-advisory-affected release, or an advisory that spans all current majors.

Common situations: A zero-day advisory covering the latest Next.js releases; upgrading immediately after a new vulnerable version shipped before a patched release is out; pinning to canary/RC versions that all fall in affected ranges.

Related errors


AI-assisted analysis of vercel/next.js@34433fd12e (2026-09-20). Data as JSON: /api/errors/162bc8667578226e. Report an issue: GitHub.

Appendix: source

Thrown at packages/next/src/lib/upgrade/prepare-upgrade.ts:549

    }
  }

  for (const major of [...latest.keys()].sort((a, b) => a - b)) {
    if (major < semver.major(source)) {
      continue
    }

    const candidate = latest.get(major)!

    if (
      semver.gt(candidate.version, source) &&
      !ranges.some((range) => semver.satisfies(candidate.version, range))
    ) {
      return candidate
    }
  }

  throw new Error('No safe Next.js update is currently available.')
}

View on GitHub (pinned to 34433fd12e)