CVE-2026-64644: Next.js: Denial of Service in the Image Optimization API using SVGs
When self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in /_next/image endpoints.
- If you are using
config.images.remotePatterns, only the patterns in that array are impacted. - If you are using
config.images.unoptimized: true, you are NOT impacted. - If you are using
config.images.loader: 'custom', you are NOT impacted. - If you are using Vercel, you are NOT impacted.
References
- github.com/advisories/GHSA-q8wf-6r8g-63ch
- github.com/vercel/next.js/commit/93cb90891402fa4c47798d03cb9e05c13233766c
- github.com/vercel/next.js/pull/96006
- github.com/vercel/next.js/releases/tag/v15.5.21
- github.com/vercel/next.js/releases/tag/v16.2.11
- github.com/vercel/next.js/security/advisories/GHSA-q8wf-6r8g-63ch
- nvd.nist.gov/vuln/detail/CVE-2026-64644
Code Behaviors & Features
Detect and mitigate CVE-2026-64644 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →