๐Ÿ” CVE Alert

CVE-2026-94483

UNKNOWN 0.0

Next.js: Server-Side Request Forgery in Image Optimization

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized image fetch to reach private IP addresses after the URL passes the allow-list check. Applications without images.remotePatterns are not affected. Administrators unable to upgrade should audit allow-listed hosts and avoid entries whose DNS records are not trusted. This issue is fixed in version 16.3.8.

CWE CWE-918
Vendor vercel
Product next.js
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for vercel next.js

Be the first to know when new unknown vulnerabilities affecting vercel next.js are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

vercel / next.js
>= 16.0.0, < 16.3.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/vercel/next.js/security/advisories/GHSA-cjq9-62q9-8jv4 github.com: https://github.com/vercel/next.js/commit/e002ad68bd676bb0ed0c87bb22e3590304763e0b github.com: https://github.com/vercel/next.js/releases/tag/v16.3.8