Server-Side Request Forgery in Open Next Cloudflare Adapter
CVE-2025-6087
7.8HIGH
What is CVE-2025-6087?
A Server-Side Request Forgery (SSRF) vulnerability exists in the Open Next Cloudflare adapter, allowing unauthenticated users to proxy arbitrary remote content via the /_next/image endpoint. This vulnerability permits attackers to load resources from any external host using the victim’s domain, leading to potential phishing risks and the exposure of internal services. Mitigations have been implemented, including restrictions on loaded content to only allow images and updates to the Cloudflare adapter. Users are encouraged to upgrade to the patched versions to safeguard against this vulnerability.
