Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
ID: 0d7df322-700d-5af0-9475-3d6dd50e9784
STIX ID: report--0d7df322-700d-5af0-9475-3d6dd50e9784
Feed Name: The Hacker News
Vercel released emergency security patches for two critical unauthenticated RCE vulnerabilities in Next.js: a libheif heap-buffer-overflow triggered by specially crafted AVIF images (affecting AVIF optimization when enabled) and a Windows-only path traversal RCE (CVE-2026-75604). Affected Next.js versions span 13.4 through 15.5.23 and 16.0 through 16.3.2; fixes are available in Next.js 15.5.24 and 16.3.3, Vercel-hosted sites are already protected, and no active exploitation had been reported at the time of the advisory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
