CVE-2025-59471: Vercel Next.js

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and that the attacker can serve or control a large image on an allowed domain. Strongly consider upgrading to 15.5.10 or 16.1.5 to reduce risk and prevent availability issues in Next applications.

Affected products

  • Vercel Next.js: from 10.0.0, before 15.5.10 (fixed in 15.5.10); from 16.0.0, before 16.1.5 (fixed in 16.1.5)

Published 2026-01-26. Last modified 2026-06-17.