< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 5 sources · 3 days · First seen · Last updated

Vercel Next.js security vulnerabilities

Overview

Vercel released security updates for Next.js to address critical vulnerabilities that could enable unauthenticated remote code execution.

One major issue involves a heap buffer overflow in the AVIF image optimization process. This flaw, rated with a CVSS v4 score of 9.5, is triggered by malicious AVIF files processed via the sharp Node package and the libheif C library. To mitigate this, the latest updates disable AVIF optimization by default until a permanent upstream fix is available.

Additionally, a Windows-specific path traversal vulnerability (CVE-2026-75604) was identified, carrying a CVSS score of 9.0. This flaw affects applications using the Pages Router or the App Router without Cache Components on Windows filesystems. Vercel noted, “There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.”

Developers are urged to update to versions 15.5.24 or 16.3.3 to protect both cloud and self-hosted deployments.

Entities

Next.js · Vercel · libheif · Sharp

Timeline

  1. 22 days ago

    [TECHNOLOGY] 3 sources
    Vercel patches critical Next.js vulnerabilities

    Vercel has issued urgent patches for Next.js to fix two critical vulnerabilities, including a Windows path traversal flaw and an AVIF heap overflow, both capable of unauthenticated remote code execution.

  2. 25 days ago

    [TECHNOLOGY] 2 sources
    Vercel releases Next.js security updates to patch critical AVIF vulnerability

    Vercel released Next.js updates 16.3.3 and 15.5.24 to patch critical vulnerabilities in the libheif library that allow remote code execution via malicious AVIF images.

Sources

blogspan.net · businesstechweekly.com · cybersecurity-news.de · it-boltwise.de · rockyharbour.ca