megachangelog
Security

WAF Emergency Release: Next.js RCE Protections (CVE-2026-75604, GHSA-2xp9-vwfh-vxw4)

Emergency update to WAF ruleset with enhanced detection for Next.js remote code execution via CVE-2026-75604 on Windows hosts and a new rule for RCE via crafted AVIF images in the Next.js Image Optimizer. Both vulnerabilities affect unauthenticated users.

This emergency release updates an existing Next.js remote code execution rule to identify CVE-2026-75604 and adds a new rule for remote code execution in the Next.js Image Optimizer via crafted AVIF images.

Key Findings

  • CVE-2026-75604 affects Windows-hosted Next.js applications using both the Pages Router and App Router without Cache Components and can lead to unauthenticated remote code execution.

  • GHSA-2xp9-vwfh-vxw4 affects the Next.js Image Optimizer and can lead to unauthenticated remote code execution when it optimizes an attacker-controlled AVIF image.

Impact

Next.js recommends updating to version 16.3.3 or 15.5.24 to address these vulnerabilities.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...2ca6cce3N/ANext.js - Remote Code Execution - CVE:CVE-2026-75604BlockN/ARule metadata description refined. Detection unchanged.
Cloudflare Managed Ruleset...80256efeN/ANext.js - Image Optimizer Remote Code Execution via Crafted AVIFN/ABlockThis is a new detection.
wafsecuritynext.jsrcecve

Source: original entry ↗