CVE-2026-44577Medium· 5.9▾ SunlitNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memor…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
0.7% → 0.7%
Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability is fixed in 15.5.16 and 16.2.5.
next.js >= 10.0.0, < 15.5.16next.js >= 16.0.0, < 16.2.5Upgrade past the affected range:
next.js 16.2.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44579High· 7.5Next.js is a React framework for building full-stack web applications
CVE-2026-45109High· 7.5Next.js is a React framework for building full-stack web applications
CVE-2026-44578High· 8.6Next.js is a React framework for building full-stack web applications
CVE-2026-44575High· 7.5Next.js is a React framework for building full-stack web applications
CVE-2026-44574High· 8.1Next.js is a React framework for building full-stack web applications
CVE-2026-44573High· 7.5Next.js is a React framework for building full-stack web applications