MEDIUM 5.9 npm
Denial of Service condition in Next.js image optimization
GHSA-g77x-44xx-532m · CVE-2024-47831
Published · Modified
Description
Impact
The image optimization feature of Next.js contained a vulnerability which allowed for a potential Denial of Service (DoS) condition which could lead to excessive CPU consumption.
Not affected:
- The
next.config.jsfile is configured withimages.unoptimizedset totrueorimages.loaderset to a non-default value. - The Next.js application is hosted on Vercel.
Patches
This issue was fully patched in Next.js 14.2.7. We recommend that users upgrade to at least this version.
Workarounds
Ensure that the next.config.js file has either images.unoptimized, images.loader or images.loaderFile assigned.
Credits
Brandon Dahler (brandondahler), AWS
Dimitrios Vlastaras
Ready to move
Start Securing
Free, no credit card | First findings in minutes