Denial of Service Vulnerability in Next.js Applications by Vercel
CVE-2025-59471

5.9MEDIUM

Key Information:

Vendor

Vercel

Status
Vendor
CVE Published:
26 January 2026

What is CVE-2025-59471?

A denial of service vulnerability has been identified in self-hosted Next.js applications configured with remotePatterns for the Image Optimizer. The vulnerability arises when the image optimization endpoint (/_next/image) handles external images by loading them entirely into memory without a maximum size restriction. This flaw can be exploited by an attacker who successfully serves a large image from an allowed domain, leading to out-of-memory conditions in the application. To mitigate this risk, it is highly recommended to upgrade to Next.js version 15.5.10 or 16.1.5.

Affected Version(s)

next 10.0

next 11.0

next 12.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.