Impact
The vulnerability is a Server‑Side Request Forgery in Next.js’s image optimization feature. An attacker can supply a remote URL that matches the configured images.remotePatterns allow‑list. Although the URL passes the allow‑list check, the framework performs DNS resolution on that URL, which can resolve to private IP addresses. This permits the application to fetch and optimize images from internal or otherwise protected services, thereby giving an attacker the ability to discover, read, or potentially modify resources behind the network boundary.
Affected Systems
Vercel’s Next.js framework versions from 16.0.0 up through 16.3.8 are affected. Applications that do not enable the images.remotePatterns configuration are not impacted. Versions 16.3.8 and later contain the fix.
Risk and Exploitability
The CVSS base score of 8.3 indicates high severity, yet the EPSS score is unavailable so current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via SSRF: an attacker crafts a URL that complies with images.remotePatterns, causing the server to resolve it to a private address and retrieve data from that internal source. The flaw exploits improper DNS validation after allow‑list enforcement, leading to potential confidentiality and integrity impacts for internal services.
OpenCVE Enrichment