Server-Side Request Forgery in Open Next Cloudflare Adapter
CVE-2025-6087

7.8HIGH

Key Information:

Vendor

Cloudflare

Status
Vendor
CVE Published:
16 June 2025

What is CVE-2025-6087?

A Server-Side Request Forgery (SSRF) vulnerability exists in the Open Next Cloudflare adapter, allowing unauthenticated users to proxy arbitrary remote content via the /_next/image endpoint. This vulnerability permits attackers to load resources from any external host using the victim’s domain, leading to potential phishing risks and the exposure of internal services. Mitigations have been implemented, including restrictions on loaded content to only allow images and updates to the Cloudflare adapter. Users are encouraged to upgrade to the patched versions to safeguard against this vulnerability.

References

CVSS V4

Score:
7.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Edward Coristine
.