criticalVulnerability

GHSA-2xp9-vwfh-vxw4

A vulnerability in the underlying `libheif` library used by `sharp` which Next.js uses for image optimization can lead to remote code execution when AVIF files are optimized. Until a fix has propagated, optimization of AVIF files is disabled.

Properties

ghsa_id
GHSA-2xp9-vwfh-vxw4
severity
critical
summary
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
cve_id
GHSA-2xp9-vwfh-vxw4
is_ghsa_only
true
ghsa_published
2026-09-08T21:21:12Z
source_url
https://github.com/advisories/GHSA-2xp9-vwfh-vxw4
ghsa_updated
2026-09-08T21:21:13Z

Related Entities (4)

AFFECTS (1)

[Software]npm/next

HAS_WEAKNESS (1)

[Weakness]Dependency on Vulnerable Third-Party Component

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/next

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-2xp9-vwfh-vxw4 — Ninja Signal Threat Intelligence | Ninja Signal