{"id":"CVE-2024-47831","aliases":["GHSA-g77x-44xx-532m"],"url":"https://o3.security/vulnerability/CVE-2024-47831","summary":"Next.js image optimization has Denial of Service condition","details":"Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in the image optimization feature which allows for a potential Denial of Service (DoS) condition which could lead to excessive CPU consumption. Neither the `next.config.js` file that is configured with `images.unoptimized` set to `true` or `images.loader` set to a non-default value nor the Next.js application that is hosted on Vercel are affected. This issue was fully patched in Next.js `14.2.7`. As a workaround, ensure that the `next.config.js` file has either `images.unoptimized`, `images.loader` or `images.loaderFile` assigned.","published":"2024-10-14T18:04:25.927Z","modified":"2026-08-12T03:51:20.712276518Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"next","fixedVersion":"14.2.7"}],"fix":{"url":"https://github.com/vercel/next.js/commit/d11cbc9ff0b1aaefabcba9afe1e562e0b1fde65a","label":"vercel/next.js@d11cbc9"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47831.json"},{"type":"ADVISORY","url":"https://github.com/vercel/next.js/security/advisories/GHSA-g77x-44xx-532m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47831"},{"type":"FIX","url":"https://github.com/vercel/next.js/commit/d11cbc9ff0b1aaefabcba9afe1e562e0b1fde65a"},{"type":"PACKAGE","url":"https://github.com/vercel/next.js"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:20.712276518Z"}}