megachangelog
Security15.5.10, 15.6.0-canary.61, 16.1.5, 16.2.0-canary.9

Security patches for CVE-2025-59471 and CVE-2025-59472

Two medium-severity denial-of-service vulnerabilities affecting self-hosted Next.js applications can cause server crashes through memory exhaustion. Vercel-hosted applications are unaffected and require no action. Fixes are available in Next.js 15.5.10, 15.6.0-canary.61, 16.1.5, and 16.2.0-canary.9.

Two medium-severity denial-of-service vulnerabilities were discovered in self-hosted Next.js applications. Both issues can cause server crashes through memory exhaustion under specific configurations. No data exposure or privilege escalation is possible. 

Applications hosted on Vercel’s platform are not affected by these issues, and require no customer action.

(CVSS 5.9) affects the Image Optimizer when external image optimization is enabled via . The endpoint loads remote images fully into memory without enforcing a maximum size, allowing an attacker to trigger out-of-memory conditions using very large images hosted on an allowed domain.CVE-2025-59471remotePatterns/_next/image

(CVSS 5.9) affects applications with Partial Pre-Rendering (PPR) enabled in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests and processes attacker-controlled data, allowing memory exhaustion through unbounded request buffering or decompression.CVE-2025-59472

CVE-2025-59471

CVE-2025-59472

Both vulnerabilities can cause the Node.js process to terminate due to memory exhaustion, resulting in application downtime.

requires external image optimization to be enabled and the attacker to control a large image hosted on an allowed domain.CVE-2025-59471

only affects applications running with the or configuration options and as an environment variable.CVE-2025-59472experimental.ppr: truecacheComponents: trueNEXT_PRIVATE_MINIMAL_MODE=1

Fixed in:

Workaround:

For self-hosted deployments unable to upgrade immediately:

We thank for their responsible disclosure through our bug bounty program.Andrew MacPherson

Read more

Summary

Affected Versions

Impact

Resolution

Credit

References

  • Next.js versions >=10 through <15.5.10

  • Next.js versions >=16 through <16.1.5

  • Next.js versions >=15 through <15.6.0-canary.61

  • Next.js versions >=16 through <16.1.5

  • 15.5.10

  • 15.6.0-canary.61

  • 16.1.5

  • 16.2.0-canary.9

  • Restrict or remove untrusted remotePatterns

  • Disable Partial Pre-Rendering or minimal mode

  • Apply strict request size limits at the reverse proxy layer

securitydenial-of-servicememorynext.jscve

Source: original entry ↗

More from Vercel

Follow Vercel to get its new changes in your feed and email digest.

Feature

OpenAI Decisions API now available on AI Gateway

OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.

ai-gatewayopenaiapidecisionssdks
Feature

Timestamp attributes now supported in Vercel Flags

Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.

flagstargetingfeaturetimestampscampaigns
Feature

Glyph Cluster now available in stealth on AI Gateway

Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.

ai-gatewaymodelscodingstealth
See all Vercel changes →