Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Imag…
Medium CVSS 5.3
Summary
Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in /_next/image endpoints.Only config.images.remotePatterns is affected, and just the patterns in that array, whereas config.images.…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/vercel/next.js/commit/93cb90891402fa4c47798d03cb9e05c13233766c Patch
- https://github.com/vercel/next.js/pull/96006 Issue Tracking
- https://github.com/vercel/next.js/releases/tag/v15.5.21 Product
- https://github.com/vercel/next.js/releases/tag/v16.2.11 Product
- https://github.com/vercel/next.js/security/advisories/GHSA-q8wf-6r8g-63ch Vendor Advisory
Timeline
- nvd_ingest NVD