Remote DNS Resolution Vulnerability in Next.js Framework by Vercel
CVE-2026-94483

8.3HIGH

Key Information:

Vendor

Vercel

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-94483?

The Next.js framework, utilized for building full-stack web applications, contains a security vulnerability that affects versions ranging from 16.0.0 to 16.3.8. This issue permits an attacker to exploit the Image Optimization feature, which can follow attacker-controlled DNS resolutions for remote URLs. If the remote URL aligns with specified image remote patterns, it may inadvertently allow the optimized image fetch process to access private IP addresses after passing the allow-list verification. Applications that utilize the images.remotePatterns feature are at risk. Administrators unable to implement the recommended version upgrade should diligently audit their allow-listed hosts and ensure that DNS records are trustworthy.

Affected Version(s)

next.js >= 16.0.0, < 16.3.8

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.