Server-Side Request Forgery (SSRF) in Next.js - CVE-2026-94483
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform server-side request forgery.
The vulnerability exists due to improper validation of allow-listed remote URLs in Image Optimization when processing an attacker-controlled allow-listed remote URL. A remote attacker can provide an attacker-controlled allow-listed remote URL to perform server-side request forgery.
Only applications with images.remotePatterns configured are affected.