Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
PoC publicVercelOur summary
Vercel has shipped emergency patches for Next.js to address two critical vulnerabilities that permit unauthenticated remote code execution. One flaw, tracked as CVE-2026-75604, is a path traversal issue affecting applications using both the Pages and App Routers on Windows file systems, while the other stems from a heap buffer overflow in the libheif library when processing crafted AVIF images. The security fixes are available in versions 15.5.24 and 16.3.3, which were released ahead of schedule due to the severity of the issues; self-hosted users on Windows are urged to upgrade immediately as no workaround exists, whereas Vercel-hosted applications are already protected.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.