目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-64644— Next.js 图像优化 API 基于 SVG 拒绝服务漏洞

CVSS 6.3 · Medium

Possible ATT&CK Techniques 1AI

T1496 · Resource Hijacking

Affected Version Matrix 2

ベンダープロダクトVersion Rangeステータス
vercelnext.js>= 15.5.0, < 15.5.21affected
>= 16.0.0, < 16.2.11affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-64644の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Next.js: Denial of Service in the Image Optimization API using SVGs
ソース: CVE Program / CVE List V5
脆弱性説明
Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in /_next/image endpoints.Only config.images.remotePatterns is affected, and just the patterns in that array, whereas config.images.unoptimized: true, config.images.loader: 'custom', and Vercel are not impacted. This issue has been fixed in versions 15.5.21 and 16.2.11.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
算法复杂性
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
vercelnext.js >= 15.5.0, < 15.5.21 -

II. CVE-2026-64644の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-64644のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-64644 补丁与修复 (2)

CVE-2026-64644 厂商安全公告 (1)

CVE-2026-64644 厂商页面 (1)

Same Patch Batch · vercel · 2026-07-27 · 9 CVEs total

CVE-2026-646428.3 HIGHNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single l
CVE-2026-646458.3 HIGHNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostn
CVE-2026-646498.3 HIGHNext.js: Server-Side Request Forgery in Server Actions on Custom Servers
CVE-2026-646418.2 HIGHNext.js: Denial of Service in App Router using Server Actions
CVE-2026-646436.3 MEDIUMNext.js: Unauthenticated Disclosure of Internal Server Function endpoints
CVE-2026-646466.3 MEDIUMNext.js: Unbounded Server Action payload in Edge runtime
CVE-2026-646476.3 MEDIUMNext.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies
CVE-2026-646486.0 MEDIUMNext.js: Response Body Cache Confusion for Requests Containing Bodies

IV. 関連脆弱性

V. CVE-2026-64644へのコメント

まだコメントはありません


コメントを残す