Description
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized image fetch to reach private IP addresses after the URL passes the allow-list check. Applications without images.remotePatterns are not affected. Administrators unable to upgrade should audit allow-listed hosts and avoid entries whose DNS records are not trusted. This issue is fixed in version 16.3.8.
Published: 2026-10-02
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery that allows access to internal network resources
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a Server‑Side Request Forgery in Next.js’s image optimization feature. An attacker can supply a remote URL that matches the configured images.remotePatterns allow‑list. Although the URL passes the allow‑list check, the framework performs DNS resolution on that URL, which can resolve to private IP addresses. This permits the application to fetch and optimize images from internal or otherwise protected services, thereby giving an attacker the ability to discover, read, or potentially modify resources behind the network boundary.

Affected Systems

Vercel’s Next.js framework versions from 16.0.0 up through 16.3.8 are affected. Applications that do not enable the images.remotePatterns configuration are not impacted. Versions 16.3.8 and later contain the fix.

Risk and Exploitability

The CVSS base score of 8.3 indicates high severity, yet the EPSS score is unavailable so current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via SSRF: an attacker crafts a URL that complies with images.remotePatterns, causing the server to resolve it to a private address and retrieve data from that internal source. The flaw exploits improper DNS validation after allow‑list enforcement, leading to potential confidentiality and integrity impacts for internal services.

Generated by OpenCVE AI on October 2, 2026 at 16:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Next.js v16.3.8 or later, where the issue is resolved.
  • Audit all entries in images.remotePatterns and eliminate any that could resolve to private IP ranges; ensure that only trusted, publicly resolvable domains remain.
  • If immediate upgrade is not possible, temporarily disable image optimization or tighten the allow‑list to a strict set of known domains, and consider blocking outbound connections to internal IP ranges at the network level.

Generated by OpenCVE AI on October 2, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Vercel
Vercel next.js
Vendors & Products Vercel
Vercel next.js

Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Description Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized image fetch to reach private IP addresses after the URL passes the allow-list check. Applications without images.remotePatterns are not affected. Administrators unable to upgrade should audit allow-listed hosts and avoid entries whose DNS records are not trusted. This issue is fixed in version 16.3.8.
Title Next.js: Server-Side Request Forgery in Image Optimization
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-02T15:18:38.684Z

Reserved: 2026-09-21T17:25:42.292Z

Link: CVE-2026-94483

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T16:16:51.473

Modified: 2026-10-02T16:16:51.473

Link: CVE-2026-94483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:30:14Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)