next is vulnerable to Denial of Service (DoS)
63
Medium Risk
When self-hosting Next.js with the default image loader, the Image Optimization API can fetch and optimize remotely hosted images when remote patterns are configured. A malicious SVG served from an allowed remote source forces expensive processing on the /_next/image endpoint, causing CPU exhaustion. Repeated requests let an unauthenticated caller degrade availability of the optimization endpoint. The fix avoids the expensive metadata work for such images. Deployments on Vercel, with unoptimized images, or with a custom loader are not affected.
You are affected if you are using a version that falls within the vulnerable range and you self-host with the default image loader and have configured config.images.remotePatterns.
next is vulnerable to Denial of Service (DoS) in versions 15.5.0 - 15.5.20 and 16.0.0 - 16.2.10.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant