highCVSS 6.5Vulnerability

CVE-2026-94483

## Impact An attacker-controlled, allow-listed remote URL can lead to server-side request forgery (e.g. to private IPs) during Image Optimization. ## Workaround Audit allow-listed remote URLs in `images.remotePatterns` (see https://nextjs.org/docs/app/getting-started/images#remote-images) for hosts that may not be trusted with their DNS entries. If no `images.remotePatterns` are configured, your app is not affected.

Properties

summary
Next.js has Server-Side Request Forgery in Image Optimization
severity
high
cvss_score
6.5
retrieved_at
2026-10-07T22:35:46+00:00
ghsa_published
2026-10-07T20:30:55Z
source_url
https://github.com/advisories/GHSA-cjq9-62q9-8jv4
ghsa_updated
2026-10-07T20:30:56Z
ghsa_id
GHSA-cjq9-62q9-8jv4
last_source
GitHub Advisory Database
cve_id
CVE-2026-94483
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
signal_observed_at
2026-10-07T22:35:46+00:00
is_ghsa_only
false

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/next

AFFECTS (1)

→[Software]npm/next

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-94483 (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal