← nejvýznamnější zprávy · všechny zprávy

poslední zpráva

SPOJENO PŘES CVE

Next.js: PoC pubblico per lo sfruttamento della CVE-2026-94545

Disponibile Proof of Concept (PoC) per lo sfruttamento della vulnerabilità CVE-2026-94545 – già sanata dal vendor – presente in next/og ImageResponse di Next.js. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato remoto, in determinate condizioni, di eseguire codice arbitrario sui sistemi interessati.

Číst originál na CSIRT Itálie (ACN) →

2 zprávy z 2 zdrojů · první · zachyceno CZ · EN/orig

Next.js IT FI

tg: zranitelnost

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-94545 – – –

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.5.

Jak se o tom psalo 2

  1. · CSIRT Itálie (ACN) IT nadpis události

    Next.js: PoC pubblico per lo sfruttamento della CVE-2026-94545

    Disponibile Proof of Concept (PoC) per lo sfruttamento della vulnerabilità CVE-2026-94545 – già sanata dal vendor – presente in next/og ImageResponse di Next.js. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato remoto, in determinate condizioni, di eseguire codice arbitrario sui sistemi interessati.

  2. · zachyceno · NCSC-FI FI

    Next.js - Remote Code Execution Vulnerability

    Classification: Severe, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv4.0: 9.5, CVEs: CVE-2026-94545, Summary: A vulnerability in the Node.js implementation of ImageResponse can lead to remote code execution when an application passes attacker-controlled values into SVG content, attributes or styles during image generation. The vulnerability affects Next.js versions 16.2.0 through 16.3.5. Applications using the Edge implementation of ImageResponse are not affected.