Next.js patches two critical flaws enabling unauthenticated remote code execution
Vercel patched two critical unauthenticated remote code execution flaws in Next.js, the popular React framework that sees tens of millions of downloads a week. One stems from the upstream libheif library used for image processing and triggers when the framework optimizes an attacker-supplied AVIF image; the patched releases disable AVIF optimization until the upstream fix lands. The second, CVE-2026-75604, is a path traversal affecting Next.js servers running on a Windows filesystem in certain router configurations, with no workaround. Fixes are in versions 15.5.24 and 16.3.3, and applications hosted on Vercel are already protected. No exploitation had been reported at disclosure.
- Check
- Update Next.js to 15.5.24 or 16.3.3, rebuild production containers, and refresh dependency lockfiles, since the AVIF flaw comes through an upstream image library bundled in your build.
- Affected
- Self-hosted Next.js applications using image optimization or running on Windows filesystems (CVE-2026-75604 and the AVIF flaw); an unauthenticated attacker can achieve remote code execution, though Vercel-hosted apps are already protected.
- Fix
- Patch and rebuild, disable AVIF optimization until updated, review exposure of the image optimization API and public upload paths, and watch logs for traversal patterns and unusual AVIF processing on Windows-hosted instances.