Intel

AIKIDO-2026-10754

next is vulnerable to Denial of Service

Denial of ServiceCVE-2026-44577 Published May 7, 2026

59

Medium Risk

This Affects:

JSnext
10.0.0 - 15.5.15
Fixed in 15.5.16
16.0.0 - 16.2.4
Fixed in 16.2.5
Are you affected? Scan for Free

TL;DR

The Image Optimization API can load local image responses fully into memory without consistent maximum-size enforcement. Large local assets requested through optimization endpoints can exhaust process memory. This permits remote resource exhaustion in affected self-hosted configurations. The fix enforces response body limits for internal image fetches and aborts oversized streams.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

next is vulnerable to Denial of Service in versions 10.0.0 - 15.5.15 and 16.0.0 - 16.2.4.

How to fix this

Upgrade the next library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform