Image Optimization API Vulnerability in Next.js from Vercel
CVE-2026-64644
6.3MEDIUM
What is CVE-2026-64644?
Next.js is vulnerable when using the default image loader with self-hosted configurations. In specific versions, the Image Optimization API can inadvertently handle maliciously crafted remote images, leading to CPU exhaustion in the /_next/image endpoints. This affects only the config.images.remotePatterns settings and can be exploited if they are improperly configured. The issue has been remedied in the latest releases, ensuring enhanced security against such exploits.
Affected Version(s)
next.js >= 15.5.0, < 15.5.21 < 15.5.0, 15.5.21
next.js >= 16.0.0, < 16.2.11 < 16.0.0, 16.2.11