Security patches for CVE-2025-59471 and CVE-2025-59472
Two medium-severity denial-of-service vulnerabilities affecting self-hosted Next.js applications can cause server crashes through memory exhaustion. Vercel-hosted applications are unaffected and require no action. Fixes are available in Next.js 15.5.10, 15.6.0-canary.61, 16.1.5, and 16.2.0-canary.9.
Two medium-severity denial-of-service vulnerabilities were discovered in self-hosted Next.js applications. Both issues can cause server crashes through memory exhaustion under specific configurations. No data exposure or privilege escalation is possible.
Applications hosted on Vercel’s platform are not affected by these issues, and require no customer action.
(CVSS 5.9) affects the Image Optimizer when external image optimization is enabled via . The endpoint loads remote images fully into memory without enforcing a maximum size, allowing an attacker to trigger out-of-memory conditions using very large images hosted on an allowed domain.CVE-2025-59471remotePatterns/_next/image
(CVSS 5.9) affects applications with Partial Pre-Rendering (PPR) enabled in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests and processes attacker-controlled data, allowing memory exhaustion through unbounded request buffering or decompression.CVE-2025-59472
CVE-2025-59471
CVE-2025-59472
Both vulnerabilities can cause the Node.js process to terminate due to memory exhaustion, resulting in application downtime.
requires external image optimization to be enabled and the attacker to control a large image hosted on an allowed domain.CVE-2025-59471
only affects applications running with the or configuration options and as an environment variable.CVE-2025-59472experimental.ppr: truecacheComponents: trueNEXT_PRIVATE_MINIMAL_MODE=1
Fixed in:
Workaround:
For self-hosted deployments unable to upgrade immediately:
We thank for their responsible disclosure through our bug bounty program.Andrew MacPherson
Summary
Affected Versions
Impact
Resolution
Credit
References
Next.js versions >=10 through <15.5.10
Next.js versions >=16 through <16.1.5
Next.js versions >=15 through <15.6.0-canary.61
Next.js versions >=16 through <16.1.5
15.5.1015.6.0-canary.6116.1.516.2.0-canary.9
Restrict or remove untrusted
remotePatternsDisable Partial Pre-Rendering or minimal mode
Apply strict request size limits at the reverse proxy layer
Source: original entry ↗
More from Vercel
Follow Vercel to get its new changes in your feed and email digest.
OpenAI Decisions API now available on AI Gateway
OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.
Timestamp attributes now supported in Vercel Flags
Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.
Glyph Cluster now available in stealth on AI Gateway
Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.