Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8wf-6r8g-63ch

Опубликовано: 22 июл. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.3

Описание

Next.js: Denial of Service in the Image Optimization API using SVGs

Impact

When self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in /_next/image endpoints.

  • If you are using config.images.remotePatterns, only the patterns in that array are impacted.
  • If you are using config.images.unoptimized: true, you are NOT impacted.
  • If you are using config.images.loader: 'custom', you are NOT impacted.
  • If you are using Vercel, you are NOT impacted.

Workarounds

If you cannot upgrade immediately, you can avoid the expensive work by setting config.experimental.imgOptSkipMetadata : true.

Пакеты

Наименование

next

npm
Затронутые версииВерсия исправления

>= 15.5.0, < 15.5.21

15.5.21

Наименование

next

npm
Затронутые версииВерсия исправления

>= 16.0.0, < 16.2.11

16.2.11

EPSS

Процентиль: 41%
0.00522
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-407

Связанные уязвимости

CVSS3: 7.5
redhat
5 дней назад

A flaw was found in Next.js, a React framework. When self-hosting Next.js with the default image loader and configured to optimize remotely hosted images, a remote attacker could exploit the Image Optimization API. By providing malicious images, the attacker can cause CPU exhaustion, leading to a Denial of Service (DoS) in the /_next/image endpoints. This vulnerability specifically affects configurations using config.images.remotePatterns.

CVSS3: 5.3
nvd
5 дней назад

Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in /_next/image endpoints.Only config.images.remotePatterns is affected, and just the patterns in that array, whereas config.images.unoptimized: true, config.images.loader: 'custom', and Vercel are not impacted. This issue has been fixed in versions 15.5.21 and 16.2.11.

EPSS

Процентиль: 41%
0.00522
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-407