
What is CVE-2026-94483?
CVE-2026-94483 is a server-side request forgery flaw in the Image Optimization feature of Next.js, the React framework maintained by Vercel. It is classified as CWE-918.
Image Optimization fetches a remote image on the server and re-encodes it. Before fetching, it checks the requested URL against the images.remotePatterns allow-list. The flaw is that the allow-list check and the fetch resolve DNS separately, so a host that passes the check can resolve to a different address by the time the fetch happens. An attacker who controls DNS for an allow-listed hostname can point it at a private address and have the server fetch from internal infrastructure on their behalf.
The vulnerability carries a CVSS v4.0 base score of 8.3 (High). Confidentiality impact is high, integrity impact is low, and availability impact is none, which matches the shape of the flaw: it reads from places it should not reach rather than altering or disabling anything.
Two things hold the score below critical and both matter for triage. Attack complexity is rated high and attack requirements are rated present, because exploitation depends on the attacker controlling DNS resolution for a hostname the target has already chosen to allow-list. This is not a flaw an untargeted scanner trips over. It is a flaw that matters when an allow-listed host is one the organization does not fully control, such as a partner CDN, a marketing platform, a former vendor’s domain, or a hostname that has since lapsed.
What assets are affected by CVE-2026-94483?
The flaw affects Next.js from 16.0.0 up to but not including 16.3.8. Version 16.3.8 carries the fix.
Applications without images.remotePatterns configured are not affected at all. The vendor is explicit on this point, and it is the single most useful triage question here. An application that only optimizes images from its own project directory never reaches the vulnerable path. An application that optimizes images loaded from external hosts does.
In practice an affected asset is a server-rendered Next.js site that pulls imagery from somewhere else: product photography from a commerce backend, editorial images from a headless CMS, avatars from an identity provider, campaign assets from a digital asset manager. That pattern is normal in exactly the sites that choose Next.js, because decoupling content from presentation is much of the reason to use it.
The practical question is not whether the allow-list exists but what is on it. Entries accumulate. A hostname added for a campaign three years ago, pointed at a vendor who has since been replaced, is still a trusted fetch target and may now be a domain someone else can register. The vendor’s own interim guidance is to audit allow-listed hosts and remove any whose DNS records are not trusted, which is a configuration review rather than a code change.
None of this is externally visible. A scan can identify Next.js but not the framework version, not whether remote patterns are configured, and not what is in them.
What does our data show about exposure patterns?

Exposure in this set is led by Industrials at 20.0% of observed assets, with Consumer Discretionary contributing 14.9% and Communication Services 11.0%. The remaining sectors together account for 54.2%.
The notable feature is again the flatness. More than half the observed assets sit outside the top three sectors, spread across consumer staples, energy, financials, information technology, and health care without any one dominating.
That shape is almost identical to what the same framework produced in a separate exposure set three weeks ago, which is a useful confirmation rather than a coincidence. Next.js is not a vertical application tied to one business process, so its footprint tracks which organizations have rebuilt a customer-facing web property recently rather than any industry’s technology stack.
This set is also unusually evenly distributed across organizations. Unlike most exposure data, where one or two estates dominate and the sector chart mostly reflects their size, no single estate here accounts for even a tenth of the observed assets. The pattern is broad adoption rather than concentrated deployment, which means the sector shares are closer to a genuine signal than usual.
The assets were identified by service fingerprint rather than by confirmed version detection. Only a small slice carry a version in the service record, so the population running Next.js is far broader than the population where this flaw is reachable, and the gap is wider than usual because reachability here depends on configuration that no external scan can see.
One detail in the version-identified slice is worth acting on. Version 16.3.6 appears among the releases observed, and it was the upgrade target for a separate Next.js flaw disclosed in late September. Teams that patched that issue promptly landed on a release that is still inside the affected range for this one. Anyone who upgraded in the last few weeks should check that they went far enough rather than assuming a recent patch covers both.
Are fixes available?
Yes. Next.js 16.3.8 contains the fix, and the upgrade is the complete remediation. For most applications this is a routine package bump within the 16 line, with none of the major-version friction that the 16.2 line carried for the earlier advisory.
Organizations that cannot upgrade immediately have a meaningful interim option, which is unusual for an SSRF. Because exploitation requires an allow-listed hostname whose DNS the attacker can influence, auditing images.remotePatterns and removing entries whose DNS is not trusted closes the practical path. Removing the configuration entirely takes the application out of scope.
That audit is worth doing regardless of patch status. The upgrade fixes the resolution flaw, but an allow-list containing hostnames the organization no longer controls is a standing liability that will resurface in other forms.
Defenders should confirm the version their build actually ships rather than relying on a lockfile entry, since a lockfile records what was resolved at install time and not what a deployed artifact contains.
Are there any other recommended actions to take?
Until patching is confirmed, defenders should:
- Identify which Next.js applications have
images.remotePatternsconfigured - Audit every allow-listed host and confirm the organization trusts its DNS
- Remove entries for vendors, campaigns, or domains no longer in use
- Verify that recently patched applications went past 16.3.8 rather than stopping earlier
- Restrict egress from image optimization workloads to known external ranges
- Monitor image optimization requests for remote URLs resolving to private addresses
How can CyCognito help your organization?
CyCognito published an Emerging Threat Advisory for CVE-2026-94483 in the CyCognito platform and is actively researching enhanced detection capabilities for this vulnerability.
To learn how CyCognito can help your organization reduce external exposure and manage emerging threats more effectively, contact us to request a demo.