GHSA-cjq9-62q9-8jv4: SSRF
Impact
An attacker-controlled, allow-listed remote URL can lead to server-side request forgery (e.g. to private IPs) during Image Optimization.
Workaround
Audit allow-listed remote URLs in images.remotePatterns (see https://nextjs.org/docs/app/getting-started/images#remote-images) for hosts that may not be trusted with their DNS entries. If no images.remotePatterns are configured, your app is not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/nextto a version that resolves this vulnerability.Fixed in 16.3.8 - Compensating control
Audit the allow-listed remote URLs in `images.remotePatterns` and remove or restrict hosts whose DNS entries are not trusted, to prevent Image Optimization requests to private IPs.
Event History
Frequently Asked Questions
Which deployments are affected?
Only applications that configure `images.remotePatterns` are affected. If no `images.remotePatterns` are configured, the application is not affected.
What must an attacker control to exploit this issue?
The attacker needs an allow-listed remote URL whose host has DNS entries that are not trusted. During Image Optimization, that URL can then cause server-side requests, including requests to private IP addresses.
What can be done if patching is not immediately possible?
Audit every host allowed by `images.remotePatterns` and remove or restrict hosts that may not be trusted to control their DNS entries.