Skip to main content
← Back to blog

Next.js Security Update: Critical AVIF and Windows RCE Risks Patched

Vercel patched two critical Next.js vulnerabilities that can lead to unauthenticated remote code execution under specific conditions, including Windows-hosted deployments and AVIF optimization paths. Engineering teams should upgrade immediately to patched LTS versions and review image-processing exposure.

#nextjs#cve#rce#websecurity#developers#patchmanagement
Next.js Security Update: Critical AVIF and Windows RCE Risks Patched

Next.js Critical Security Release: What Defenders Should Do

What happened

Vercel released patches for two critical Next.js issues that can allow unauthenticated remote code execution in specific deployment conditions. One issue affects Windows-hosted servers through a path traversal class, while another is tied to AVIF image optimization through an upstream parsing dependency.

Who is affected

Teams running self-hosted Next.js applications are most exposed, particularly Windows-hosted deployments and applications that explicitly enable AVIF optimization.

Why it matters

Next.js is widely used in production web stacks. Critical vulnerabilities in framework and dependency processing paths can become high-priority patching events for both application security and platform operations teams.

Technical details

  • CVE-2026-75604: critical Windows filesystem path traversal issue (CVSS 9.0)
  • AVIF optimization chain: critical upstream libheif overflow advisory (GHSA-g89c-p67h-r497), reflected in Next.js security guidance (GHSA-2xp9-vwfh-vxw4)
  • Affected ranges include pre-patch 15.5.x and 16.3.x branches
  • Fixed versions: Next.js 15.5.24 and 16.3.3
  • Exploitation status at publication: no confirmed in-the-wild exploitation reported for these August issues

Recommended actions

  • Upgrade immediately to supported patched versions.
  • Prioritize Windows-hosted instances and internet-facing applications.
  • Review whether image/avif optimization is enabled and assess exposure.
  • Validate WAF, logging, and anomaly monitoring for image-processing and traversal probes.
  • Track Vercel and upstream advisories for further hardening updates.

Sources

  • https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html
  • https://nextjs.org/blog/august-2026-security-release
  • https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36