Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 5 sources · 3 days · First seen · Last updated
Vercel Next.js security vulnerabilities
Overview
Vercel released security updates for Next.js to address critical vulnerabilities that could enable unauthenticated remote code execution.
One major issue involves a heap buffer overflow in the AVIF image optimization process. This flaw, rated with a CVSS v4 score of 9.5, is triggered by malicious AVIF files processed via the sharp Node package and the libheif C library. To mitigate this, the latest updates disable AVIF optimization by default until a permanent upstream fix is available.
Additionally, a Windows-specific path traversal vulnerability (CVE-2026-75604) was identified, carrying a CVSS score of 9.0. This flaw affects applications using the Pages Router or the App Router without Cache Components on Windows filesystems. Vercel noted, “There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.”
Developers are urged to update to versions 15.5.24 or 16.3.3 to protect both cloud and self-hosted deployments.
Entities
Timeline
-
22 days ago
[TECHNOLOGY] 3 sourcesVercel patches critical Next.js vulnerabilitiesVercel has issued urgent patches for Next.js to fix two critical vulnerabilities, including a Windows path traversal flaw and an AVIF heap overflow, both capable of unauthenticated remote code execution.
-
25 days ago
[TECHNOLOGY] 2 sourcesVercel releases Next.js security updates to patch critical AVIF vulnerabilityVercel released Next.js updates 16.3.3 and 15.5.24 to patch critical vulnerabilities in the libheif library that allow remote code execution via malicious AVIF images.
Sources
blogspan.net · businesstechweekly.com · cybersecurity-news.de · it-boltwise.de · rockyharbour.ca