The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade next to version 16.3.8 or higher.
next is a react framework.
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the Image Optimization remote fetch, which resolves and requests an allowlisted remote URL without constraining the address that name resolves to, so a host permitted by images.remotePatterns can direct the fetch at an internal address. An attacker can make the server issue requests to private network addresses and read the responses back through the image endpoint, by controlling the DNS records of a host that matches an allowlist entry so the name resolves to that internal address at fetch time. This requires images.remotePatterns to be configured with at least one host whose DNS entries the attacker controls or can influence, so applications with no images.remotePatterns configured are unaffected.
This vulnerability can be avoided by removing from images.remotePatterns any host whose DNS entries are not trusted.