Next.js Oct 14 security update: redeploy, then test your Sume webhook
Next.js will ship an out-of-band security update on Oct 14. Prepare your Sume webhook receiver now, then prove it still verifies after you redeploy.

Next.js will publish an out-of-band security update on Wednesday, October 14, 2026, so plan one redeploy that day and prove your Sume webhook receiver still verifies signatures afterwards. Sume's "Send test" delivery does that without spending a generation job.
The framework's announcement is short. It says what is coming, not what is affected. This post covers what you can prepare before the advisories exist, and what to check after you deploy.
What Next.js has said so far
Everything below comes from the announcement page (read 2026-10-10). Affected versions and upgrade instructions are not published yet, so do not guess a version number.
| Item | What the page says |
|---|---|
| Release date | Wednesday, October 14, 2026, an out-of-band update |
| Scope | Three vulnerabilities in upstream dependencies |
| Severity | Two Critical, one High |
| Origin | Two fixes were postponed from the September security release because of upstream coordination |
| Advisories | Published with the update: impact, affected versions, upgrade instructions |
| Ask | Upgrade to a patched version as soon as it is available |
Prepare before the 14th
A Sume integration on Next.js usually has two server-side pieces: a route that submits jobs with your API key, and a route that receives webhooks. Both redeploy with the framework, so get the boring parts ready now.
- Confirm your lockfile is committed and your CI can build and deploy in one step, so the patched version is a one-line change.
- Confirm the webhook signing secret is in your host's environment as SUME_COM_WEBHOOK_SIGNING_SECRET. Read it from the Webhooks tab of the dashboard or from GET /v1/webhooks/signing-secret.
- Find a recent completed job id. You will use it to redeliver a real event after the deploy.
- Check that a status poll can fill any gap. Sume retries a delivery up to 10 attempts with 10 seconds per attempt, so a short deploy window should not lose events, but the poll is the recovery path if it does.
After you deploy: two different checks
Redeliver also works after Sume has used all automatic attempts, and it does not use one of the 10. Because your handler treats job_id as the idempotency key, a redelivered event for a job you already stored must be a no-op, which is the behavior you want to see.
| Action | How | What it proves |
|---|---|---|
| Send test | Dashboard Webhooks tab, or POST /v1/webhooks/test-deliveries with account:write | Your URL is reachable and the signature verifies. Sends a dummy signed webhook.test payload with no job_id. |
| Redeliver | POST /v1/jobs/{job_id}/webhook/redeliver with jobs:write | Your handler processes a real terminal event (job.completed, job.failed or job.canceled) with a fresh timestamp and signature. |
A receiver that returns fast
The check is only meaningful if the route reads the raw body before parsing. This is the shape from the SDK webhook docs; recordTerminalRun is your own function.
import { verifyWebhook } from "@sume-com/sdk";
export async function POST(request: Request) {
const body = await request.text(); // raw, before any JSON.parse
const ok = await verifyWebhook({
body,
headers: request.headers,
secret: process.env.SUME_COM_WEBHOOK_SIGNING_SECRET!,
});
if (!ok) return new Response("bad signature", { status: 401 });
const event = JSON.parse(body);
await recordTerminalRun(event.request_id, event); // dedupe on request_id
return new Response(null, { status: 204 }); // fast 2xx, then work
}If the signature fails after the deploy
Compare the x-sume-webhook-secret-fingerprint header on the delivery with the fingerprint shown next to the secret in the dashboard. A mismatch means the new deployment has the wrong secret, not that the framework changed anything. The fingerprint is the only part that is safe to paste into a ticket.
Sources
Related posts
More in Developers
- Node 26.11 --process-timeout exits 124: the Sume job keeps running
Node 26.11.0 adds --process-timeout, which kills a script with exit code 124. A Sume job it was waiting on keeps running and billing, so save the polling URL.
- Node script for a 9:16 TikTok video: check the model, then submit
A Node 20 fetch script that confirms a Sume model lists 9:16 and your duration, submits one 12-second 720p job, and saves an MP4 that fits TikTok's API limits.
- Test a Sume poll loop with node:test mock.timers, no real sleeping
Use node:test mock.timers to prove your poll loop waits next_poll_after_seconds, falls back to 2 s, and never polls early. A runnable test, no network.
- One length gate for six ad platforms: caps table and Sume plan
Reels 15 min, Stories 60 min, TikTok 10 min, LinkedIn 30 min, Pinterest 5 min, Snap 180 s. Check one Sume Timeline length against all six with the plan call.
Written by Sume