Remote DNS Resolution Vulnerability in Next.js Framework by Vercel
CVE-2026-94483
What is CVE-2026-94483?
The Next.js framework, utilized for building full-stack web applications, contains a security vulnerability that affects versions ranging from 16.0.0 to 16.3.8. This issue permits an attacker to exploit the Image Optimization feature, which can follow attacker-controlled DNS resolutions for remote URLs. If the remote URL aligns with specified image remote patterns, it may inadvertently allow the optimized image fetch process to access private IP addresses after passing the allow-list verification. Applications that utilize the images.remotePatterns feature are at risk. Administrators unable to implement the recommended version upgrade should diligently audit their allow-listed hosts and ensure that DNS records are trustworthy.
Affected Version(s)
next.js >= 16.0.0, < 16.3.8