CVE-2026-94483High· 8.3▾ TwilightNext.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized image fetch to reach private IP addresses after the URL passes the allow-list check. Applications without images.remotePatterns are not affected. Administrators unable to upgrade should audit allow-listed hosts and avoid entries whose DNS records are not trusted. This issue is fixed in version 16.3.8.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44578High· 8.6Next.js is a React framework for building full-stack web applications
CVE-2026-94544Medium· 6.3Next.js is a React framework for building full-stack web applications
CVE-2026-94485Medium· 6.3Next.js is a React framework for building full-stack web applications
CVE-2026-94543Medium· 6.3Next.js is a React framework for building full-stack web applications
CVE-2026-94486Low· 2.3Next.js is a React framework for building full-stack web applications
CVE-2026-94484Medium· 6.3Next.js is a React framework for building full-stack web applications