CVE-2025-59471: Vercel Next.js
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and that the attacker can serve or control a large image on an allowed domain. Strongly consider upgrading to 15.5.10 or 16.1.5 to reduce risk and prevent availability issues in Next applications.
Affected products
- Vercel Next.js: from 10.0.0, before 15.5.10 (fixed in 15.5.10); from 16.0.0, before 16.1.5 (fixed in 16.1.5)
Published 2026-01-26. Last modified 2026-06-17.