Nextjs, Server-Side Request Forgery, CVE-2026-94483 (High) -DC-Oct2026-2855

Listen to this Post

CVE-2026-94483 is a high-severity server-side request forgery vulnerability residing within the Image Optimization feature of the Next.js framework.
When Next.js handles image optimization requests, it fetches and re-encodes remote images from external sources.
To control permissible external hosts, developers use the images.remotePatterns configuration directive to define an allow-list of approved domains.
The security flaw emerges when an application includes an allow-listed remote URL or host that is not fully controlled or trusted by the organization.
Attackers can exploit this by interacting with the Image Optimization API using carefully crafted request parameters pointing to internal network resources.
Because the framework trusts the allow-listed domain configuration, the server initiates an outbound network request to the specified target.
This mechanism bypasses standard perimeter defenses, allowing external entities to probe private IP ranges, local loopback interfaces, or internal microservices.
If an organization lists broad wildcard domains, partner CDNs, or lapsed hostnames, malicious actors can leverage them as pivoting points.
Consequently, internal APIs that lack authentication can be queried, exposing sensitive infrastructure data or leading to severe reconnaissance outcomes.
Applications that do not utilize images.remotePatterns or only optimize local project assets are entirely unaffected by this specific vulnerability.
Mitigation requires a thorough audit of all configured remote patterns, removing untrusted hosts, and upgrading the framework to secure versions.

DailyCVE Form:

Platform: Next.js
Version: Older versions
Vulnerability: Request forgery
Severity: High level
date: Sep 30

Prediction: Patched version

What Undercode Say:

Audit Next.js configuration for remote patterns
grep -rn "remotePatterns" next.config.js
// Example vulnerable remotePatterns setup
module.exports = {
images: {
remotePatterns: [
{
protocol: 'https',
hostname: '',
},
],
},
}

Exploit: (Educational Purposes!)

Probing internal network endpoints via Image Optimization API
curl -I "http://vulnerable-app.com/_next/image?url=http://127.0.0.1:8080/admin&w=640&q=75"

Protection: from this CVE

Audit allow-listed remote URLs in images.remotePatterns for hosts that may not be trusted with their DNS entries.
Remove wildcard entries or hosts managed by third parties that are no longer actively verified.

Update Next.js to the latest patched release version.

Impact:

An attacker-controlled, allow-listed remote URL can lead to server-side request forgery (e.g. targeting private IP ranges) during Image Optimization.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top