CVE-2024-47831
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-47831 affects Next.js versions 10.x through 14.x before 14.2.7, which contain a vulnerability in the image optimization feature. This issue permits a potential Denial of Service (DoS) condition, resulting in excessive CPU consumption. The `next.config.js` file with `images.unoptimized` set to `true` or `images.loader` set to a non-default value, as well as Next.js applications hosted on Vercel, are not impacted. The vulnerability was fully remedied in Next.js 14.2.7. As a temporary measure, ensure that the `next.config.js` file includes `images.unoptimized`, `images.loader`, or `images.loaderFile` assignments.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.