Server-Side Request Forgery in Open Next Cloudflare Adapter
CVE-2025-6087
What is CVE-2025-6087?
A Server-Side Request Forgery (SSRF) vulnerability exists in the Open Next Cloudflare adapter, allowing unauthenticated users to proxy arbitrary remote content via the /_next/image endpoint. This vulnerability permits attackers to load resources from any external host using the victim’s domain, leading to potential phishing risks and the exposure of internal services. Mitigations have been implemented, including restrictions on loaded content to only allow images and updates to the Cloudflare adapter. Users are encouraged to upgrade to the patched versions to safeguard against this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
