Intel

AIKIDO-2026-262339

next is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)CVE-2026-94483 Published 5 days ago

83

High Risk

This Affects:

JSnext
16.0.0 - 16.3.7
Fixed in 16.3.8
Are you affected? Scan for Free

TL;DR

The next Image Optimization API fetches remote images when images.remotePatterns allows the host. Before connecting, it resolves the hostname and rejects private addresses, then fetches the URL with a second DNS lookup. A hostname whose DNS record changes after that check can make the server request a private address and return the response. The fix pins the connection to the addresses that were already checked.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application configures images.remotePatterns.

Background info

next is vulnerable to Server-Side Request Forgery (SSRF) in versions 16.0.0 - 16.3.7.

How to fix this

Upgrade the next library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform