Server-side request forgery (SSRF) In next
Description
Next.js has Server-Side Request Forgery in Image Optimization
Impact
An attacker-controlled, allow-listed remote URL can lead to server-side request forgery (e.g. to private IPs) during Image Optimization.
Workaround
Audit allow-listed remote URLs in images.remotePatterns (see https://nextjs.org/docs/app/getting-started/images#remote-images) for hosts that may not be trusted with their DNS entries. If no images.remotePatterns are configured, your app is not affected.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel7 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel10 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel10 | - | - | |
npm | 16.3.8 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.