Vercel Next.js
cpe:2.3:a:vercel:next.js:*:*:*:*:node.js:*:*
- 10.0.0
- 11.0.0
- 12.0.0
- 13.0.0
- 14.0.0
- 15.0.0
- 16.0.0
A denial-of-service vulnerability has been identified in self-hosted Next.js applications that use 'remotePatterns' for the Image Optimizer. The issue arises because the image optimization endpoint '/_next/image' processes external images entirely in memory without a maximum size limit. This allows an attacker to create out-of-memory conditions by requesting the optimization of excessively large images. The vulnerability requires 'remotePatterns' to be set for external domains and for the attacker to control a large image on an allowed domain.
Exploitation of this vulnerability can lead to out-of-memory conditions, causing availability issues in affected Next.js applications.
Users are strongly advised to upgrade to Next.js versions 15.5.10 or 16.1.5 to mitigate this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.