next is vulnerable to Denial of Service
59
Medium Risk
The Image Optimization API can load local image responses fully into memory without consistent maximum-size enforcement. Large local assets requested through optimization endpoints can exhaust process memory. This permits remote resource exhaustion in affected self-hosted configurations. The fix enforces response body limits for internal image fetches and aborts oversized streams.
You are affected if you are using a version that falls within the vulnerable range.
next is vulnerable to Denial of Service in versions 10.0.0 - 15.5.15 and 16.0.0 - 16.2.4.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant