{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/next.js--16.0.0--16.3.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Next.js (\u003e= 10.0.0, \u003c 15.5.24)","Next.js (\u003e= 16.0.0, \u003c 16.3.3)"],"_cs_severities":["critical"],"_cs_tags":["rce","vulnerability","web-application","nextjs"],"_cs_type":"advisory","_cs_vendors":["Vercel"],"content_html":"\u003cp\u003eA critical remote code execution (RCE) vulnerability exists in the Next.js framework, specifically within its image optimization API. The vulnerability is rooted in the third-party \u003ccode\u003elibheif\u003c/code\u003e library, which is utilized by the \u003ccode\u003esharp\u003c/code\u003e package to process AVIF image files. An unauthenticated attacker can trigger this vulnerability by submitting a maliciously crafted AVIF file to the Next.js image optimization endpoint. The flaw enables the execution of arbitrary code within the context of the application process. This vulnerability affects Next.js versions 10.0.0 through 15.5.23 and 16.0.0 through 16.3.2. As a result of the severity, defenders should prioritize patching or implementing the recommended mitigation immediately to prevent potential system compromise and data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target application utilizing Next.js for web hosting.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious AVIF image file containing a payload designed to exploit memory corruption in \u003ccode\u003elibheif\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP POST or GET request to the Next.js image optimization API endpoint (typically \u003ccode\u003e/api/next/image\u003c/code\u003e or similar paths handling image transformation).\u003c/li\u003e\n\u003cli\u003eThe Next.js application receives the malicious image file and passes it to the \u003ccode\u003esharp\u003c/code\u003e library for optimization/processing.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003esharp\u003c/code\u003e library invokes the vulnerable \u003ccode\u003elibheif\u003c/code\u003e code to parse the AVIF file.\u003c/li\u003e\n\u003cli\u003eMemory corruption occurs during the parsing of the malicious image, allowing the attacker to overwrite sensitive memory structures.\u003c/li\u003e\n\u003cli\u003eThe attacker's payload executes within the context of the application server.\u003c/li\u003e\n\u003cli\u003eFinal objective achieved: Remote code execution, facilitating potential exfiltration of environment variables, source code, or lateral movement into the internal network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to achieve full remote code execution on the server hosting the Next.js application. This compromises the confidentiality, integrity, and availability of the application and its underlying infrastructure. Given the ubiquity of Next.js in modern web development, this vulnerability poses a high risk to a vast number of enterprise, government, and consumer-facing web platforms.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately upgrade Next.js to the patched versions: 15.5.24 or 16.3.3.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not feasible, disable AVIF support in the Next.js image configuration to mitigate the attack vector.\u003c/li\u003e\n\u003cli\u003eDeploy WAF rules to inspect and filter suspicious image upload requests targeting image optimization endpoints.\u003c/li\u003e\n\u003cli\u003eConduct a review of application logs for anomalous requests to the image optimization API, specifically looking for high-frequency or large-payload image uploads.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-08T21:48:49Z","date_published":"2026-09-08T21:48:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nextjs-rce/","summary":"A critical vulnerability in the libheif dependency used by Next.js allows unauthenticated attackers to achieve remote code execution via malicious AVIF image uploads.","title":"Unauthenticated Remote Code Execution in Next.js Image Optimization API","url":"https://feed.craftedsignal.io/briefs/2026-09-nextjs-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Next.js (\u003e= 16.0.0, \u003c 16.3.3)","version":"https://jsonfeed.org/version/1.1"}