GHSA-2xp9-vwfh-vxw4Critical▾ MidnightNext.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability in the underlying libheif library used by sharp which Next.js uses for image optimization can lead to remote code execution when AVIF files are optimized.
Until a fix has propagated, optimization of AVIF files is disabled.
next >= 10.0.0, < 15.5.24next >= 16.0.0, < 16.3.3Upgrade to a patched release:
next 15.5.24next 16.3.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-75604Critical· 9.0Next.js is a React framework for building full-stack web applications
CVE-2026-64648MediumNext.js: Cache confusion of response bodies for requests with bodies
CVE-2026-64649HighNext.js: Server-Side Request Forgery in Server Actions on custom servers
CVE-2026-64641HighNext.js: Denial of Service in App Router using Server Actions
CVE-2026-64642HighNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
CVE-2026-64643MediumNext.js: Unauthenticated disclosure of internal Server Function endpoints