VYPR
Medium severity5.9GHSA Advisory· Published May 13, 2026· Updated May 13, 2026

CVE-2026-44577

CVE-2026-44577

Description

Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability is fixed in 15.5.16 and 16.2.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nextnpm
>= 10.0.0, < 15.5.1615.5.16
nextnpm
>= 16.0.0, < 16.2.516.2.5

Affected products

4
  • Vercel/Next.jsGHSA2 versions
    >= 16.0.0, < 16.2.5+ 1 more
    • (no CPE)range: >= 16.0.0, < 16.2.5
    • cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*range: >=10.0.0,<15.5.16
  • osv-coords2 versions
    < 0.51.0-r7+ 1 more
    • (no CPE)range: < 0.51.0-r7
    • (no CPE)range: >= 10.0.0, < 15.5.16

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.