Server-side Request Forgery (SSRF) Affecting next package, versions >=16.0.0 <16.3.8


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.27% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-NEXT-20366781
  • published1 Oct 2026
  • disclosed30 Sept 2026
  • creditUnknown

Introduced: 30 Sep 2026

NewCVE-2026-94483  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade next to version 16.3.8 or higher.

Overview

next is a react framework.

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the Image Optimization remote fetch, which resolves and requests an allowlisted remote URL without constraining the address that name resolves to, so a host permitted by images.remotePatterns can direct the fetch at an internal address. An attacker can make the server issue requests to private network addresses and read the responses back through the image endpoint, by controlling the DNS records of a host that matches an allowlist entry so the name resolves to that internal address at fetch time. This requires images.remotePatterns to be configured with at least one host whose DNS entries the attacker controls or can influence, so applications with no images.remotePatterns configured are unaffected.

Workaround

This vulnerability can be avoided by removing from images.remotePatterns any host whose DNS entries are not trusted.

CVSS Base Scores

version 4.0
version 3.1