Next.js Oct 14 security update: redeploy, then test your Sume webhook

Next.js will ship an out-of-band security update on Oct 14. Prepare your Sume webhook receiver now, then prove it still verifies after you redeploy.

4 min readSume
All posts

Next.js will publish an out-of-band security update on Wednesday, October 14, 2026, so plan one redeploy that day and prove your Sume webhook receiver still verifies signatures afterwards. Sume's "Send test" delivery does that without spending a generation job.

The framework's announcement is short. It says what is coming, not what is affected. This post covers what you can prepare before the advisories exist, and what to check after you deploy.

What Next.js has said so far

Everything below comes from the announcement page (read 2026-10-10). Affected versions and upgrade instructions are not published yet, so do not guess a version number.

Next.js announcement, published October 8 2026 (read 2026-10-10)
ItemWhat the page says
Release dateWednesday, October 14, 2026, an out-of-band update
ScopeThree vulnerabilities in upstream dependencies
SeverityTwo Critical, one High
OriginTwo fixes were postponed from the September security release because of upstream coordination
AdvisoriesPublished with the update: impact, affected versions, upgrade instructions
AskUpgrade to a patched version as soon as it is available

Prepare before the 14th

A Sume integration on Next.js usually has two server-side pieces: a route that submits jobs with your API key, and a route that receives webhooks. Both redeploy with the framework, so get the boring parts ready now.

  • Confirm your lockfile is committed and your CI can build and deploy in one step, so the patched version is a one-line change.
  • Confirm the webhook signing secret is in your host's environment as SUME_COM_WEBHOOK_SIGNING_SECRET. Read it from the Webhooks tab of the dashboard or from GET /v1/webhooks/signing-secret.
  • Find a recent completed job id. You will use it to redeliver a real event after the deploy.
  • Check that a status poll can fill any gap. Sume retries a delivery up to 10 attempts with 10 seconds per attempt, so a short deploy window should not lose events, but the poll is the recovery path if it does.

After you deploy: two different checks

Redeliver also works after Sume has used all automatic attempts, and it does not use one of the 10. Because your handler treats job_id as the idempotency key, a redelivered event for a job you already stored must be a no-op, which is the behavior you want to see.

Sume webhook checks (Sume docs, workflows/webhooks)
ActionHowWhat it proves
Send testDashboard Webhooks tab, or POST /v1/webhooks/test-deliveries with account:writeYour URL is reachable and the signature verifies. Sends a dummy signed webhook.test payload with no job_id.
RedeliverPOST /v1/jobs/{job_id}/webhook/redeliver with jobs:writeYour handler processes a real terminal event (job.completed, job.failed or job.canceled) with a fresh timestamp and signature.

A receiver that returns fast

The check is only meaningful if the route reads the raw body before parsing. This is the shape from the SDK webhook docs; recordTerminalRun is your own function.

import { verifyWebhook } from "@sume-com/sdk";

export async function POST(request: Request) {
  const body = await request.text(); // raw, before any JSON.parse

  const ok = await verifyWebhook({
    body,
    headers: request.headers,
    secret: process.env.SUME_COM_WEBHOOK_SIGNING_SECRET!,
  });
  if (!ok) return new Response("bad signature", { status: 401 });

  const event = JSON.parse(body);
  await recordTerminalRun(event.request_id, event); // dedupe on request_id
  return new Response(null, { status: 204 }); // fast 2xx, then work
}

If the signature fails after the deploy

Compare the x-sume-webhook-secret-fingerprint header on the delivery with the fingerprint shown next to the secret in the dashboard. A mismatch means the new deployment has the wrong secret, not that the framework changed anything. The fingerprint is the only part that is safe to paste into a ticket.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume