Skip to content
Brief Security & Trust ·

Next.js image feature flaw can let attackers reach private IP addresses

A GitHub advisory describes a server-side request forgery bug in Next.js Image Optimization.

In brief
  • GitHub's advisory database lists a request forgery flaw in Next.js Image Optimization, tracked as CVE-2026-94483. Apps without images.remotePatterns are not affected.
  • The advisory gives no severity score or affected versions in the text provided. It links to the Next.js v16.3.8 release.

The GitHub Advisory Database published a notice on 7 October 2026 about a flaw in Next.js. The bug is in Image Optimization. The advisory says a remote URL that is on an app's allow-list, but controlled by an attacker, can trigger server-side request forgery. That means the server is tricked into sending requests on the attacker's behalf, for example to private IP addresses. The flaw is tracked as CVE-2026-94483. The advisory also links to the Next.js v16.3.8 release page.

The advisory does say who is safe: apps that have no images.remotePatterns setting are not affected. For everyone else, it advises checking the allow-listed remote URLs in that setting. The risk is hosts whose DNS entries may not be trustworthy. The text gives no severity score and no list of affected versions. It does not say whether anyone has used the flaw in attacks. It links to release v16.3.8 but does not say that release contains the fix.

Teams that run Next.js and load images from outside hosts can check their configuration now. The test is simple: look for images.remotePatterns and review each host on the list. Teams that never set it are, by the advisory's account, not exposed.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: GitHub Advisory Database.