Vercel Next.js
cpe:2.3:a:vercel:next.js:*:*:*:*:node.js:*:*
- ~10
- ~11
- ~12
- ~13
- < 14.2.7
A denial-of-service vulnerability has been identified in the image optimization feature of Next.js. This issue is present in versions 10.x, 11.x, 12.x, 13.x, and in the 14.x branch prior to 14.2.7. The vulnerability allows for excessive CPU consumption, leading to potential service disruption. However, applications hosted on Vercel or those with specific configurations in the 'next.config.js' file are not affected. The vulnerability has been fully patched in Next.js version 14.2.7.
Exploitation of this vulnerability can cause excessive CPU usage, leading to a denial-of-service condition where the application becomes unresponsive or slow.
The vulnerability can be reproduced by using Next.js versions 10.x, 11.x, 12.x, 13.x, or 14.x prior to 14.2.7, and by not applying the available workarounds or patches. Once the conditions are met, the image optimization feature can be used in a way that triggers the excessive CPU consumption.
Users are advised to upgrade to Next.js version 14.2.7 or later. If an immediate upgrade is not possible, ensure that the 'next.config.js' file includes 'images.unoptimized', 'images.loader', or 'images.loaderFile'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.