CVE-2026-64644
CVE-2026-64644: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2026-64644] Denial of Service via malicious image optimization
CVE-2026-64644Source published Source updated
Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in /_next/image endpoints. Only config.images.remotePatterns is affected, and just the patterns in that array, whereas config.images.unoptimized: true, config.images.loader: 'custom', and Vercel are not impacted. This issue has been fixed in versions 15.5.21 and 16.2.11. This vulnerability specifically affects configurations using config.images.remotePatterns. This is an Important denial of service vulnerability in Next.js…
- Affected products in this advisory
- Streams for Apache Kafka 3.2.1
- streams for Apache Kafka 2
- Source-reported affected versions
- 15.5.0
- 15.5.20
- 16.0.0
- 16.2.10
- Source-reported fixed versions
- 15.5.21
- 16.2.11
- next
- RHSA-2026:54435
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.