Vercel applications are protected from Next.js August 2026 security vulnerabilities
Summary
Two vulnerabilities affecting Next.js were disclosed in the August 2026 Security Release. Next.js applications hosted on Vercel are protected and require no customer action.
Next.js August 2026 vulnerabilities
Next.js disclosed the following critical vulnerabilities:
- GHSA-2xp9-vwfh-vxw4 originates in the upstream libheif dependency and can lead to unauthenticated remote code execution when Image Optimization processes a crafted AVIF input.
- CVE-2026-75604 (GHSA-p293-qw3h-jr36) can lead to unauthenticated remote code execution on Windows-hosted Next.js servers in applications using the Pages Router and App Router without Cache Components.
After the AVIF vulnerability was identified, Vercel applied protections to its managed Image Optimization service.
Impact on Vercel deployments
Applications hosted on Vercel are protected. No upgrades, configuration changes, or redeploys are required.
- Once the AVIF vulnerability was identified, Vercel disabled AVIF optimization across its managed Image Optimization service. AVIF inputs are served as-is and do not pass through the affected processing path.
- The second vulnerability only affects servers using a Windows filesystem. Vercel's Next.js runtime uses Linux and is not affected.
Resolution for self-hosted applications
Self-hosted Next.js applications should upgrade to the appropriate patched version.
For applications running Next.js 15.x or earlier:
For applications running Next.js 16.x:
In the patched releases, AVIF images are not resized or optimized. They are served as-is until a fixed libheif version is available. There is no workaround for the Windows vulnerability; affected servers should upgrade immediately.
Credit
Thanks to the Hacktron team for responsibly disclosing the AVIF vulnerability, and to evolutionstorm and B0RI for responsibly disclosing the Windows vulnerability.