Developers.Cloudflare
Critical Vulnerabilities in .js Framework Lead to Remote Code Execution Risks
Article Content
On August 25, 2026, Next.js announced a critical security release to address two vulnerabilities affecting .js applications. The vulnerabilities, CVE-2026-75604 and GHSA-2xp9-vwfh-vxw4, allow unauthenticated remote code execution. CVE-2026-75604 specifically impacts Windows-hosted applications using both the Pages Router and App Router without Cache Components. GHSA-2xp9-vwfh-vxw4 affects the .js Image Optimizer when processing crafted AVIF images. Cloudflare released an emergency WAF update on August 26 to mitigate these vulnerabilities. Users are urged to update to versions 16.3.3 or 15.5.24 to secure their applications. The vulnerabilities pose significant risks, especially for Windows users, and there are no known workarounds for affected systems. The Next.js team collaborates with researchers to enhance security through a bug bounty program.
Key Points: • Two critical vulnerabilities in .js allow remote code execution. • CVE-2026-75604 affects Windows applications using specific routing methods. • Immediate updates to versions 16.3.3 or 15.5.24 are recommended.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.