mediumVulnerability

CVE-2026-64644

### Impact When self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in `/_next/image` endpoints. - If you are using `config.images.remotePatterns`, only the patterns in that array are impacted. - If you are using `config.images.unoptimized: true`, you are NOT impacted. - If you are using `config.images.loader: 'custom'`, you are NOT impacted. - If you are using Vercel, you are NOT impacted. ### Workarounds If you cannot upgrade immediately, you can avoid the expensive work by setting `config.experimental.imgOptSkipMetadata : true`.

Properties

ghsa_id
GHSA-q8wf-6r8g-63ch
severity
medium
summary
Next.js: Denial of Service in the Image Optimization API using SVGs
epss_score
0.00675
cve_id
CVE-2026-64644
is_ghsa_only
false
ghsa_published
2026-07-22T23:02:05Z
source_url
https://github.com/advisories/GHSA-q8wf-6r8g-63ch
epss_percentile
0.49525
ghsa_updated
2026-07-22T23:02:06Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/next

AFFECTS (1)

[Software]npm/next

HAS_WEAKNESS (1)

[Weakness]Inefficient Algorithmic Complexity

Explore deeper with Ninja Signal's threat intelligence graph