Threat Response - Critical vulnerabilities in Next.js
Dutch follows English
Next.js has released critical security updates to fix two severe vulnerabilities that could allow attackers to take complete control of your web servers [1]. If your organisation uses Windows-hosted Next.js or the Next.js Image Optimization API, we strongly recommend to apply the available updates immediately.
Description
Next.js is a popular web development framework used to build websites and web applications. Two critical security vulnerabilities have been discovered:
- A flaw in the image processing feature when handling AVIF images that attackers can exploit by uploading malicious images [2].
- A vulnerability affecting Next.js applications running on Windows servers that use both the Pages Router and App Router without Cache Components [3][4].
Impact
We estimate the impact of these vulnerabilities as high.
Both vulnerabilities allow unauthenticated remote code execution, meaning attackers can run malicious code on your servers without needing a password or any access credentials. This could allow them to steal data, install malware, disrupt services, or use your servers for further attacks. The first vulnerability affects all platforms when AVIF image optimization is enabled. The second vulnerability only affects Windows-hosted servers, not Linux or macOS systems.
Risk
We estimate the risk of these vulnerabilities as high.
These are critical severity vulnerabilities that are now publicly disclosed, which increases the likelihood that attackers will attempt to exploit them. The vulnerabilities can be exploited remotely without authentication, making them attractive targets for attackers.
Mitigation
Update Next.js to version 16.3.3 (Active LTS) or 15.5.24 (Maintenance LTS). The patched versions temporarily disable AVIF image optimization and fix the Windows-specific vulnerability. There is no workaround available for the Windows vulnerability other than updating.
What should you do?
Identify all applications using Next.js and update them to the patched versions as soon as possible. Prioritize Windows-hosted servers and applications that process user-uploaded images. Contact your development teams or vendors to ensure updates are applied promptly. Lastly, Northwave recommends to analyse systems for signs of compromise. If you are unsure your systems are compromised, we recommend to contact the Northwave CERT for assistance.
What will Northwave do?
We will monitor any developments regarding this vulnerability. If new critical information about this threat arises we will reach out to you. You can contact us by phone or send us an email if you would like additional information.
E-mail: soc@northwave-cybersecurity.com
Do you have an incident right now? Call our Incident Response Team: 00800 1744 0000
Disclaimer applies, see below.
Sources
[1] https://nextjs.org/blog/august-2026-security-release
[2] https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4
[3] https://www.cve.org/CVERecord?id=CVE-2026-75604
[4] https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36
Next.js heeft kritieke beveiligingsupdates uitgebracht om twee ernstige kwetsbaarheden te verhelpen die aanvallers in staat kunnen stellen volledige controle over uw webservers te verkrijgen [1]. Als uw organisatie gebruikmaakt van Next.js op Windows-servers of van de Next.js Image Optimization API, raden wij ten zeerste aan de beschikbare updates onmiddellijk toe te passen.
Beschrijving
Next.js is een populair webframework dat wordt gebruikt voor het bouwen van websites en webapplicaties. Er zijn twee kritieke beveiligingskwetsbaarheden ontdekt:
- Een kwetsbaarheid in de beeldverwerkingsfunctie voor AVIF-afbeeldingen, die aanvallers kunnen misbruiken door schadelijke afbeeldingen te uploaden [2].
- Een kwetsbaarheid die Next.js-applicaties treft die draaien op Windows-servers en zowel de Pages Router als de App Router gebruiken zonder Cache Components [3][4].
Impact
Wij schatten de impact van deze kwetsbaarheden in als hoog.
Beide kwetsbaarheden maken ongeauthenticeerde uitvoering van externe code (Remote Code Execution, RCE) mogelijk. Dit betekent dat aanvallers schadelijke code op uw servers kunnen uitvoeren zonder wachtwoord of andere toegangsgegevens nodig te hebben. Hierdoor kunnen zij gegevens stelen, malware installeren, diensten verstoren of uw servers gebruiken voor verdere aanvallen. De eerste kwetsbaarheid treft alle platformen waarop AVIF-afbeeldingsoptimalisatie is ingeschakeld. De tweede kwetsbaarheid treft uitsluitend Windows-servers en heeft geen invloed op Linux- of macOS-systemen.
RisicoWij schatten het risico van deze kwetsbaarheden in als hoog.
Het betreft kwetsbaarheden met een kritieke ernst die inmiddels openbaar zijn gemaakt, waardoor de kans toeneemt dat aanvallers pogingen zullen doen om deze te misbruiken. Omdat de kwetsbaarheden op afstand kunnen worden uitgebuit zonder authenticatie, vormen zij een aantrekkelijk doelwit voor kwaadwillenden.
Mitigatie
Werk Next.js bij naar versie 16.3.3 (Active LTS) of 15.5.24 (Maintenance LTS). Deze versies bevatten een oplossing voor de Windows-specifieke kwetsbaarheid en schakelen tijdelijk AVIF-afbeeldingsoptimalisatie uit. Voor de Windows-kwetsbaarheid is geen andere workaround beschikbaar dan het uitvoeren van de update.
Wat moet u doen?
Breng alle applicaties die gebruikmaken van Next.js in kaart en werk deze zo snel mogelijk bij naar de gepatchte versies. Geef hierbij prioriteit aan Windows-gehoste servers en applicaties die door gebruikers geüploade afbeeldingen verwerken. Neem contact op met uw ontwikkelteams of leveranciers om ervoor te zorgen dat de updates zo spoedig mogelijk worden doorgevoerd.Daarnaast adviseert Northwave om systemen te onderzoeken op mogelijke indicatoren van compromittering. Indien u onzeker bent of uw systemen zijn gecompromitteerd, raden wij aan contact op te nemen met het Northwave CERT voor ondersteuning en verdere analyse.
Wat zal Northwave doen?
Wij zullen verdere ontwikkelingen met betrekking tot deze kwetsbaarheid monitoren. Indien er nieuwe kritieke informatie over deze dreiging beschikbaar komt, nemen wij contact met u op. U kunt ons telefonisch bereiken of een e-mail sturen voor aanvullende informatie.
Voor aanvullende informatie kunt u ons telefonisch of per e-mail bereiken.E-mail: soc@northwave-cybersecurity.com
Heeft u op dit moment een incident? Bel ons Incident Response Team: 00800 1744 0000
Disclaimer van toepassing, zie onderaan.
Bronnen
[1] https://nextjs.org/blog/august-2026-security-release
[2] https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4
[3] https://www.cve.org/CVERecord?id=CVE-2026-75604
[4] https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36

