Product
Next.js versions 16.0.0 through 16.3.7 are susceptible to Server-Side Request Forgery (SSRF) when processing images from attacker-controlled remote URLs configured in remotePatterns.