« Volver al listado

CVE-2025-59471

Estado: AnalizadaAlta (7.5)—

A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and that the attacker can serve or control a large image on an allowed domain.

Strongly consider upgrading to 15.5.10 or 16.1.5 to reduce risk and prevent availability issues in Next applications.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:N/AC:L/PR:N sin UI permite explotación remota sin privilegios de aplicación expuesta (T1190). CWE-400 y carga sin límite en memoria causando DoS (T1499.004) por agotamiento de recursos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-59471",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-59471",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-27T14:54:47.995347Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "support@hackerone.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "vercel",
          "product": "next",
          "versions": [
            {
              "status": "affected",
              "version": "10.0",
              "lessThan": "10.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "11.0",
              "lessThan": "11.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "12.0",
              "lessThan": "12.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "13.0",
              "lessThan": "13.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "14.0",
              "lessThan": "14.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "15.0",
              "lessThan": "15.5.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "16.0",
              "lessThan": "16.1.5",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-01-26T22:15:52.890",
  "references": [
    {
      "url": "https://github.com/vercel/next.js/security/advisories/GHSA-9g9p-9gw9-jx7f",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "support@hackerone.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and that the attacker can serve or control a large image on an allowed domain.\r\n\r\nStrongly consider upgrading to 15.5.10 or 16.1.5 to reduce risk and prevent availability issues in Next applications."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de denegación de servicio existe en aplicaciones Next.js autoalojadas que tienen `remotePatterns` configurado para el Optimizador de Imágenes. El endpoint de optimización de imágenes (`/_next/image`) carga imágenes externas completamente en memoria sin aplicar un límite de tamaño máximo, permitiendo a un atacante causar condiciones de falta de memoria al solicitar la optimización de imágenes arbitrariamente grandes. Esta vulnerabilidad requiere que `remotePatterns` esté configurado para permitir la optimización de imágenes desde dominios externos y que el atacante pueda servir o controlar una imagen grande en un dominio permitido.\n\nConsidere encarecidamente actualizar a 15.5.10 o 16.1.5 para reducir el riesgo y prevenir problemas de disponibilidad en aplicaciones Next."
    }
  ],
  "lastModified": "2026-06-17T09:46:13.220",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62058253-F46E-44D1-B50A-F15BC93CF928",
              "versionEndExcluding": "15.5.10",
              "versionStartIncluding": "10.0.0"
            },
            {
              "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A242736-494D-4C26-AB21-188C2E2F39FF",
              "versionEndExcluding": "16.1.5",
              "versionStartIncluding": "16.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}