Next.js 是一个用于构建全栈 Web 应用的 React 框架。从版本 16.0.0 到 16.3.8,图像优化功能在针对远程 URL 进行图像获取时,可能跟随攻击者控制的 DNS 解析结果,即使该 URL 已通过了 的白名单检查,仍可能导致优化后的图像获取请求访问到私有 IP 地址。未配置 的应用不受此问题影响。暂时无法升级的管理员应审查已列入白名单的主机,并避免将 DNS 记录不可信的主机纳入白名单。该问题已在 16.3.8 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94484 | 6.3 MEDIUM | Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitu |
| CVE-2026-94485 | 6.3 MEDIUM | Next.js: Information disclosure in Next.js App Router metadata image routes via dynamicPar |
| CVE-2026-94544 | 6.3 MEDIUM | Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and p |
| CVE-2026-94543 | 6.3 MEDIUM | Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications |
| CVE-2026-94486 | 2.3 LOW | Next.js: Information disclosure in the Next.js development server's Model Context Protocol |
No comments yet