REDHAT-BUG-2448509: Medium severity npm/next vulnerability

Published Mar 18, 2026
·
Updated

Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (/next/image) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with images.maximumDiskCacheSize, including eviction of least-recently-used entries when the limit is exceeded. Setting maximumDiskCacheSize: 0 disables disk caching. If upgrading is not immediately possible, periodically clean .next/cache/images and/or reduce variant cardinality (e.g., tighten values for images.localPatterns, images.remotePatterns, and images.qualities).

Affected Software

1 affected component
npm/next>=10.0.0<16.1.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Next.js image optimization disk cache (/_next/image) to a version that resolves this vulnerability.

    Fixed in 16.1.7
  2. Configuration

    Set images.maximumDiskCacheSize: 0 in Next.js config to disable the disk cache for /_next/image and prevent unbounded disk growth in versions 10.0.0 through <16.1.7.

    Next.js Image Optimization images.maximumDiskCacheSize = 0
  3. Operational

    If upgrading is not immediately possible, periodically clean .next/cache/images and reduce variant cardinality by tightening values for images.localPatterns, images.remotePatterns, and images.qualities (for Next.js versions 10.0.0 through <16.1.7).

Event History

Mar 18, 2026
Data Sourced
via Red Hat·01:02 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2448509?

The severity of REDHAT-BUG-2448509 is medium with a score of 4.

2

How do I fix REDHAT-BUG-2448509?

To fix REDHAT-BUG-2448509, update your Next.js version to 16.1.7 or later.

3

What versions are affected by REDHAT-BUG-2448509?

Next.js versions from 10.0.0 up to, but not including, 16.1.7 are affected by REDHAT-BUG-2448509.

4

What is the vulnerability in REDHAT-BUG-2448509?

The vulnerability in REDHAT-BUG-2448509 involves an unbounded cache growth in the default Next.js image optimization disk cache.

5

Can REDHAT-BUG-2448509 be exploited by an attacker?

Yes, an attacker could exploit REDHAT-BUG-2448509 by generating many requests to cause excessive disk space usage.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203