Next.js Denial-of-Service Vulnerability in Image Optimizer

Vulnerability

A denial-of-service vulnerability has been identified in self-hosted Next.js applications that use 'remotePatterns' for the Image Optimizer. The issue arises because the image optimization endpoint '/_next/image' processes external images entirely in memory without a maximum size limit. This allows an attacker to create out-of-memory conditions by requesting the optimization of excessively large images. The vulnerability requires 'remotePatterns' to be set for external domains and for the attacker to control a large image on an allowed domain.

Impact

Exploitation of this vulnerability can lead to out-of-memory conditions, causing availability issues in affected Next.js applications.

Remediation

Users are strongly advised to upgrade to Next.js versions 15.5.10 or 16.1.5 to mitigate this vulnerability.

Added: Jan 26, 2026, 10:28 PM
Updated: Jan 26, 2026, 10:28 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
6.4
remediation
7.7
relevance
2.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.