github opennextjs/opennextjs-cloudflare @opennextjs/cloudflare@1.20.7

5 hours ago

Patch Changes

  • #1403 dc3c0ab Thanks @aa-sikkkk! - fix: replace the whole loadCustomCacheHandlers body so Next.js 16.3 chunks don't throw ReferenceError

    Next.js 16.3 rewrote loadCustomCacheHandlers: the declaration that binds cacheHandlers now also binds
    cacheMaxMemorySize, and the native method body consumes both. The composable cache patch replaced only that
    declaration, so on the minified runtime chunks (dist/compiled/next-server/*.runtime.prod.js) the surviving
    native code referenced bindings that were no longer declared. Every request to the Worker then failed with
    ReferenceError: <minified identifier> is not defined inside loadCustomCacheHandlers (site-wide 500s on
    Next.js 16.3.x), while builds stayed green because the unminified next-server.js short-circuits on
    if (!cacheHandlers) return before the orphaned binding is read.

    The patch now replaces the whole method body while preserving its signature and wires the composable cache
    registry to the static require() as before, so no native reference to a dropped binding can survive. The
    rule still matches pre-16.3 chunks, so older Next.js versions are unaffected.

  • #1399 2b3e3a1 Thanks @JT1974! - fix: throw MODULE_NOT_FOUND from the stub of a missing optional dependency

    With React 18, every Pages Router page rendered by the Worker failed with TypeError: Cannot read properties of undefined (reading 'contexts'), caused by Error: Missing optional dependency "react-dom/server.edge". React 18 has no react-dom/server.edge, and Next.js falls back to react-dom/server.browser only when the error carries the MODULE_NOT_FOUND code. The stub now sets that code, so the fallback works again.

  • #1406 8ea9eb9 Thanks @mgarbacz! - fix: only rename esbuild's __require helper, not __require properties

    Restoring esbuild's __require helper to a bare require was a text replacement over the
    whole bundle, so it also rewrote unrelated __require members. @rollup/plugin-commonjs
    emits exports.__require lazy-init wrappers, whose declarations the replacement never
    matched — leaving the two halves disagreeing and throwing
    TypeError: __webpack_require__(...).require is not a function when such a package was
    imported during SSR. Packages built that way (for example smartystreets-javascript-sdk)
    500'd every route. The rename now skips property accesses.

  • #1404 ca4415b Thanks @vicb! - chore: require Next.js 15.5.26 or 16.3.6

    Raise the supported Next.js version floor to 15.5.26 and 16.3.6. Next.js 16.2.0 through 16.3.5 are affected
    by the critical next/og remote code execution vulnerability CVE-2026-94545.

  • #1404 ca4415b Thanks @vicb! - chore: bump @opennextjs/aws to 4.1.6

    See details at https://github.com/opennextjs/opennextjs-aws/releases/tag/v4.1.6

Don't miss a new opennextjs-cloudflare release

NewReleases is sending notifications on new releases.