What is CVE-2026-64644?
CVE-2026-64644 affects self-hosted Next.js instances using the default image loader, where the Image Optimization API can optimize remotely hosted images if explicitly configured (not enabled by default). This impacts versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, potentially leading to unauthorized remote image handling. Review your configuration and apply the appropriate patch to mitigate the risk.
Azərbaycanca: CVE-2026-64644 Next.js framework'ünün self-hosted mühitlərində default image loader istifadə edildikdə, xüsusi konfiqurasiya ilə aktivləşdirilə bilən Image Optimization API-nin uzaqdan yerləşdirilmiş şəkilləri optimallaşdırmasına yol açır. Bu, 15.5.0-15.5.20 və 16.0.0-16.2.10 versiyalarına təsir göstərir, istismar uzaq şəkil yükləmələrinə əsaslanır. Mühiti qorumaq üçün konfiqurasiyanı yoxlamalı və müvafiq yenilənməni tətbiq etməlisiniz.
FAQ2
Which versions of Next.js are affected by CVE-2026-64644?
CVE-2026-64644 affects Next.js versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10.
Does CVE-2026-64644 require specific configuration to be exploited?
Yes, this vulnerability can only be exploited in self-hosted environments using the default image loader when the Image Optimization API is explicitly configured to optimize remotely hosted images.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.