CVE-2026-94483
Next.js: Server-Side Request Forgery in Image Optimization
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized image fetch to reach private IP addresses after the URL passes the allow-list check. Applications without images.remotePatterns are not affected. Administrators unable to upgrade should audit allow-listed hosts and avoid entries whose DNS records are not trusted. This issue is fixed in version 16.3.8.
| CWE | CWE-918 |
| Vendor | vercel |
| Product | next.js |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for vercel next.js
Be the first to know when new unknown vulnerabilities affecting vercel next.js are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
vercel / next.js
>= 16.0.0, < 16.3.8