{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/next.js--16.0.0--16.3.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2026-94483"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Next.js (\u003e= 16.0.0, \u003c 16.3.8)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Vercel"],"content_html":"\u003cp\u003eNext.js versions 16.0.0 through 16.3.7 contain a Server-Side Request Forgery (SSRF) vulnerability in the Image Optimization component (CVE-2026-94483). The vulnerability arises when the application is configured to allow remote images via the \u003ccode\u003eimages.remotePatterns\u003c/code\u003e setting. An attacker can supply a malicious or attacker-controlled URL that is technically permitted by the allow-list but resolves to internal, private network addresses or restricted services. During the image optimization process, the server performs a request to the provided URL, allowing the attacker to probe the internal network or interact with services accessible to the Next.js server. This vulnerability does not affect applications that do not explicitly configure \u003ccode\u003eimages.remotePatterns\u003c/code\u003e.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to perform unauthorized requests from the server's network context. This can lead to the exposure of internal-only metadata services (such as AWS/GCP instance metadata), internal API endpoints, or other private network resources that are otherwise unreachable from the public internet. The scope of the potential damage depends on the network architecture and the services reachable from the application server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching and configuration audits to mitigate SSRF risks.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Next.js to version 16.3.8 or later to address CVE-2026-94483.\u003c/li\u003e\n\u003cli\u003eAudit the \u003ccode\u003eimages.remotePatterns\u003c/code\u003e configuration in your \u003ccode\u003enext.config.js\u003c/code\u003e file. Remove any host patterns that are not strictly necessary or that resolve to infrastructure potentially controlled by third parties who could manipulate DNS records.\u003c/li\u003e\n\u003cli\u003eImplement network-level egress filtering on the application server to restrict outbound connections to only known, required external endpoints, preventing the server from reaching internal RFC1918 address spaces.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:49:01Z","date_published":"2026-10-07T22:49:01Z","id":"https://feed.craftedsignal.io/briefs/2026-10-nextjs-ssrf/","summary":"Next.js versions 16.0.0 through 16.3.7 are susceptible to Server-Side Request Forgery (SSRF) when processing images from attacker-controlled remote URLs configured in remotePatterns.","title":"Next.js Image Optimization SSRF Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-10-nextjs-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Next.js (\u003e= 16.0.0, \u003c 16.3.8)","version":"https://jsonfeed.org/version/1.1"}