Image Optimization API Vulnerability in Next.js from Vercel
CVE-2026-64644

6.3MEDIUM

Key Information:

Vendor

Vercel

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64644?

Next.js is vulnerable when using the default image loader with self-hosted configurations. In specific versions, the Image Optimization API can inadvertently handle maliciously crafted remote images, leading to CPU exhaustion in the /_next/image endpoints. This affects only the config.images.remotePatterns settings and can be exploited if they are improperly configured. The issue has been remedied in the latest releases, ensuring enhanced security against such exploits.

Affected Version(s)

next.js >= 15.5.0, < 15.5.21 < 15.5.0, 15.5.21

next.js >= 16.0.0, < 16.2.11 < 16.0.0, 16.2.11

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.