The GitHub Advisory Database published a notice on 7 October 2026 about a flaw in Next.js. The bug is in Image Optimization. The advisory says a remote URL that is on an app's allow-list, but controlled by an attacker, can trigger server-side request forgery. That means the server is tricked into sending requests on the attacker's behalf, for example to private IP addresses. The flaw is tracked as CVE-2026-94483. The advisory also links to the Next.js v16.3.8 release page.
The advisory does say who is safe: apps that have no images.remotePatterns setting are not affected. For everyone else, it advises checking the allow-listed remote URLs in that setting. The risk is hosts whose DNS entries may not be trustworthy. The text gives no severity score and no list of affected versions. It does not say whether anyone has used the flaw in attacks. It links to release v16.3.8 but does not say that release contains the fix.
Teams that run Next.js and load images from outside hosts can check their configuration now. The test is simple: look for images.remotePatterns and review each host on the list. Teams that never set it are, by the advisory's account, not exposed.