Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaws in Next.js Allow Remote Code Execution

Critical Flaws in Next.js Allow Remote Code Execution

Posted on August 27, 2026 By CWS

Vercel has issued important security updates addressing two critical vulnerabilities in the Next.js framework. These flaws allow unauthorized remote code execution, posing significant risks if not promptly mitigated. The vulnerabilities stem from an AVIF image processing issue and a path traversal flaw affecting Windows-based servers.

Windows Path Traversal Vulnerability

The path traversal issue, identified as CVE-2026-75604 with a CVSS score of 9.0, impacts Next.js applications using both the Pages Router and App Router on Windows servers that lack Cache Components. The flaw does not affect Linux or macOS deployments. Vercel advises immediate upgrades for Windows-hosted applications as no workarounds exist.

Updates are available in Next.js 15.5.24 (Maintenance LTS) and 16.3.3 (Active LTS), released on August 25, 2026. Users can upgrade via npm commands to ensure their systems are secure. Notably, Vercel-hosted applications automatically receive protection from these vulnerabilities without needing upgrades.

AVIF Image Processing Flaw

The second vulnerability pertains to the AVIF image processing functionality in Next.js, using the sharp package dependent on the libheif library. A critical heap buffer overflow in libheif can trigger remote code execution when processing malicious AVIF images. This flaw, tracked under GHSA-2xp9-vwfh-vxw4, affects Next.js versions 10.0.0 through 15.5.23 and all 16.x versions up to 16.3.2.

Libheif’s vulnerability lies in the image scaling code, where a crafted AVIF file can cause buffer overflow, leading to potential exploitation. The patch disables AVIF optimization in Next.js until a fix from libheif is implemented. Researchers rootxharsh and KarimPwnz provided a proof-of-concept for this vulnerability.

Ongoing Security Measures

Vercel’s swift response, including moving the patch release forward by a day due to an additional critical vulnerability, underscores their commitment to security. This August update, part of Vercel’s monthly security cadence initiated in July 2026, is the second formal release, following a July update that addressed nine vulnerabilities.

Despite the recent surge in security disclosures for Next.js, including the React2Shell deserialization flaw in December 2025, no exploits of the August vulnerabilities have been reported as of August 27, 2026. Vercel’s proactive measures, alongside ongoing vulnerability research, aim to fortify the Next.js framework against emerging threats.

The Hacker News Tags:AVIF flaw, CVE-2026-75604, heap buffer overflow, image processing, libheif, Next.js, remote code execution, Security, software patch, Vercel, web framework, Windows vulnerability

Post navigation

Previous Post: How Stolen AWS Credentials Can Lead to Major Security Breaches
Next Post: AI Security’s Future Hinges on Comprehensive Data

Related Posts

The Hidden Weaknesses in AI SOC Tools that No One Talks About The Hidden Weaknesses in AI SOC Tools that No One Talks About The Hacker News
Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks The Hacker News
AI-Powered Zero-Day Exploit Bypasses 2FA Security AI-Powered Zero-Day Exploit Bypasses 2FA Security The Hacker News
Vercel Data Breach, DDoS Takedown, New Android Threats Vercel Data Breach, DDoS Takedown, New Android Threats The Hacker News
Cisco Firewall Flaw Exploited, Risks Sensitive Data Exposure Cisco Firewall Flaw Exploited, Risks Sensitive Data Exposure The Hacker News
China-Based APT UAT-7810 Enhances ORB Network with LONGLEASH China-Based APT UAT-7810 Enhances ORB Network with LONGLEASH The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark