Skip to content
Brief Security & Trust ·

Next.js image routes ignore a setting meant to exclude some pages

A GitHub advisory says some Next.js metadata image routes skip the dynamicParams option.

In brief
  • GitHub's advisory database says some Next.js image routes skip the dynamicParams setting in webpack-built App Router apps. Images can be requested for pages a developer excluded.
  • The advisory gives no severity, affected versions or details of what leaks. It links to CVE-2026-94485 and the Next.js v16.3.8 release page.

The GitHub Advisory Database published a notice on 7 October 2026 about Next.js, a web framework. It covers apps that use the App Router and are built with webpack. Image routes for page metadata, named opengraph-image and twitter-image, do not obey a setting called dynamicParams, the advisory says. So an attacker can ask for images tied to pages the developer left out on purpose. The advisory calls this information disclosure and links CVE-2026-94485.

Normally, generateStaticParams lists the pages a site builds ahead of time. The dynamicParams setting then decides whether other values get served. A developer who excludes a page expects it to stay out of reach. The advisory reports that the image routes skip this control. It gives no severity rating, no affected versions and no detail on what the images could reveal. It does not say whether attackers have used the flaw. It links the Next.js v16.3.8 release page without saying what changed.

Leaving a page off the build list is an access decision, and here one route type did not enforce it. Teams can ask three things. Which dynamic routes do we exclude on purpose? Do their generated images show data about a single record? Do we build with webpack?

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: GitHub Advisory Database.