GHSA-q8wf-6r8g-63chMedium

Next.js: Denial of Service in the Image Optimization API using SVGs

Published
July 22, 2026
Last Modified
July 22, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

When self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in /_next/image endpoints.

  • If you are using config.images.remotePatterns, only the patterns in that array are impacted.
  • If you are using config.images.unoptimized: true, you are NOT impacted.
  • If you are using config.images.loader: 'custom', you are NOT impacted.
  • If you are using Vercel, you are NOT impacted.

Workarounds

If you cannot upgrade immediately, you can avoid the expensive work by setting config.experimental.imgOptSkipMetadata : true.

🎯 Affected products2

  • npm/next:>= 15.5.0, < 15.5.21
  • npm/next:>= 16.0.0, < 16.2.11

🔗 References (6)