CVE-2026-64644
### Impact When self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in `/_next/image` endpoints. - If you are using `config.images.remotePatterns`, only the patterns in that array are impacted. - If you are using `config.images.unoptimized: true`, you are NOT impacted. - If you are using `config.images.loader: 'custom'`, you are NOT impacted. - If you are using Vercel, you are NOT impacted. ### Workarounds If you cannot upgrade immediately, you can avoid the expensive work by setting `config.experimental.imgOptSkipMetadata : true`.
Properties
- ghsa_id
- GHSA-q8wf-6r8g-63ch
- severity
- medium
- summary
- Next.js: Denial of Service in the Image Optimization API using SVGs
- epss_score
- 0.00675
- cve_id
- CVE-2026-64644
- is_ghsa_only
- false
- ghsa_published
- 2026-07-22T23:02:05Z
- source_url
- https://github.com/advisories/GHSA-q8wf-6r8g-63ch
- epss_percentile
- 0.49525
- ghsa_updated
- 2026-07-22T23:02:06Z
Related Entities (5)
ENRICHED_BY (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph