|
12084 | 12084 | "https://github.com/vercel/next.js/releases/tag/v16.2.11" |
12085 | 12085 | ] |
12086 | 12086 | }, |
| 12087 | + { |
| 12088 | + "atOrAbove": "10.0.0", |
| 12089 | + "below": "15.5.24", |
| 12090 | + "severity": "critical", |
| 12091 | + "cwe": [ |
| 12092 | + "CWE-1395" |
| 12093 | + ], |
| 12094 | + "identifiers": { |
| 12095 | + "summary": "Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used", |
| 12096 | + "githubID": "GHSA-2xp9-vwfh-vxw4" |
| 12097 | + }, |
| 12098 | + "info": [ |
| 12099 | + "https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497", |
| 12100 | + "https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4", |
| 12101 | + "https://github.com/vercel/next.js/pull/97875", |
| 12102 | + "https://github.com/vercel/next.js/pull/97931", |
| 12103 | + "https://github.com/vercel/next.js/commit/3a15b4ac6ac8e70b1a9b18ecc18e8434462899b3", |
| 12104 | + "https://github.com/vercel/next.js/commit/409772ec807def20132d251ad48fd8d8ad4c73c2", |
| 12105 | + "https://github.com/vercel/next.js/commit/7a5937a8ab20b89d0a961f75eabb11577f5d5998", |
| 12106 | + "https://github.com/vercel/next.js/releases/tag/v15.5.24", |
| 12107 | + "https://github.com/vercel/next.js/releases/tag/v16.3.3" |
| 12108 | + ] |
| 12109 | + }, |
| 12110 | + { |
| 12111 | + "atOrAbove": "13.4.0", |
| 12112 | + "below": "15.5.24", |
| 12113 | + "severity": "critical", |
| 12114 | + "cwe": [ |
| 12115 | + "CWE-22" |
| 12116 | + ], |
| 12117 | + "identifiers": { |
| 12118 | + "summary": "Next.js: Unauthenticated Remote Code Execution on windows-hosted servers", |
| 12119 | + "githubID": "GHSA-p293-qw3h-jr36", |
| 12120 | + "CVE": [ |
| 12121 | + "CVE-2026-75604" |
| 12122 | + ] |
| 12123 | + }, |
| 12124 | + "info": [ |
| 12125 | + "https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36", |
| 12126 | + "https://github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b", |
| 12127 | + "https://github.com/vercel/next.js/commit/b0f3460a92b955d3ca41fccff9a525a2b910fbf3", |
| 12128 | + "https://github.com/vercel/next.js/releases/tag/v15.5.24", |
| 12129 | + "https://github.com/vercel/next.js/releases/tag/v16.3.3" |
| 12130 | + ] |
| 12131 | + }, |
12087 | 12132 | { |
12088 | 12133 | "atOrAbove": "15.6.0-canary.0", |
12089 | 12134 | "below": "15.6.0-canary.59", |
|
12966 | 13011 | "https://github.com/vercel/next.js/releases/tag/v15.5.21", |
12967 | 13012 | "https://github.com/vercel/next.js/releases/tag/v16.2.11" |
12968 | 13013 | ] |
| 13014 | + }, |
| 13015 | + { |
| 13016 | + "atOrAbove": "16.0.0", |
| 13017 | + "below": "16.3.3", |
| 13018 | + "severity": "critical", |
| 13019 | + "cwe": [ |
| 13020 | + "CWE-1395" |
| 13021 | + ], |
| 13022 | + "identifiers": { |
| 13023 | + "summary": "Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used", |
| 13024 | + "githubID": "GHSA-2xp9-vwfh-vxw4" |
| 13025 | + }, |
| 13026 | + "info": [ |
| 13027 | + "https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497", |
| 13028 | + "https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4", |
| 13029 | + "https://github.com/vercel/next.js/pull/97875", |
| 13030 | + "https://github.com/vercel/next.js/pull/97931", |
| 13031 | + "https://github.com/vercel/next.js/commit/3a15b4ac6ac8e70b1a9b18ecc18e8434462899b3", |
| 13032 | + "https://github.com/vercel/next.js/commit/409772ec807def20132d251ad48fd8d8ad4c73c2", |
| 13033 | + "https://github.com/vercel/next.js/commit/7a5937a8ab20b89d0a961f75eabb11577f5d5998", |
| 13034 | + "https://github.com/vercel/next.js/releases/tag/v15.5.24", |
| 13035 | + "https://github.com/vercel/next.js/releases/tag/v16.3.3" |
| 13036 | + ] |
| 13037 | + }, |
| 13038 | + { |
| 13039 | + "atOrAbove": "16.0.0", |
| 13040 | + "below": "16.3.3", |
| 13041 | + "severity": "critical", |
| 13042 | + "cwe": [ |
| 13043 | + "CWE-22" |
| 13044 | + ], |
| 13045 | + "identifiers": { |
| 13046 | + "summary": "Next.js: Unauthenticated Remote Code Execution on windows-hosted servers", |
| 13047 | + "githubID": "GHSA-p293-qw3h-jr36", |
| 13048 | + "CVE": [ |
| 13049 | + "CVE-2026-75604" |
| 13050 | + ] |
| 13051 | + }, |
| 13052 | + "info": [ |
| 13053 | + "https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36", |
| 13054 | + "https://github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b", |
| 13055 | + "https://github.com/vercel/next.js/commit/b0f3460a92b955d3ca41fccff9a525a2b910fbf3", |
| 13056 | + "https://github.com/vercel/next.js/releases/tag/v15.5.24", |
| 13057 | + "https://github.com/vercel/next.js/releases/tag/v16.3.3" |
| 13058 | + ] |
12969 | 13059 | } |
12970 | 13060 | ], |
12971 | 13061 | "extractors": { |
|
0 commit comments