@cloudflare/next-on-pages is vulnerable to Server-Side Request Forgery (SSRF)
60
Medium Risk
Due to a vulnerability in the image optimization functionality of next, the package is vulnerable to server-side request forgery (SSRF). Protocol-relative URLs are not treated as actual relative URLs.
You are affected if you are using a @cloudflare/next-on-pages version which is within vulnerability ranges.
@cloudflare/next-on-pages is vulnerable to Server-Side Request Forgery (SSRF) in versions 1.4.0 - 1.12.0.
Upgrade the @cloudflare/next-on-pages library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant