Junglewise Threat Intelligence

CVE-2026-27980: Vercel Next.js unbounded next/image disk cache growth

CVE-2026-27980 · Severity: medium · CVSS 4 · Published 2026-03-17

Technologies: Vercel Next.js. Vendors: Vercel.

Executive brief

Next.js is a popular web framework used to build React applications. The built-in image optimization feature caches processed images to disk without a limit, and an attacker can trigger the creation of many unique cached variants by requesting images with different parameters. This exhausts disk space on the server, causing the application to become unavailable. Organizations using Vercel's hosting platform are not affected, only those running Next.js on their own infrastructure.

Technical details

The vulnerability is an uncontrolled resource consumption issue (CWE-400) in Next.js's default image optimization disk cache located at /_next/image. The root cause is the absence of a configurable size limit on the cache directory. An attacker can request image optimizations with many different parameters (quality, format, dimensions) to force generation and storage of distinct cache entries. The attack requires only network access and no authentication or privileges. The fix introduces an LRU (least-recently-used) eviction policy via a new `images.maximumDiskCacheSize` configuration parameter; when the limit is exceeded, least-recently-used cached images are evicted. Setting this value to 0 disables disk caching entirely. Patches are available in Next.js versions 15.5.14 and 16.1.7 and later.

Affected products

  • Vercel Next.js >=10.0.0, <15.5.14 or >=16.0.0-beta.0, <16.1.7

Timeline

  • 2026-03-17: disclosed: Advisory published
  • 2026-02-20: patched: Fix committed; released in v15.5.14 and v16.1.7
  • 2026-03-16: other: Release v16.1.7 published

References

Related threats