ZÉROJOUR

The zero-day paper — printed from structured content, not scraped prose.
Permanent editionPublic dataset · Sanity GROQGHSA × CISA KEV
next (npm) · published 2026-09-08

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

GHSA-2xp9-vwfh-vxw4 — CVSS 0/10. Fix: upgrade to 15.5.24.
Package
next
Ecosystem
npm

A vulnerability in the underlying `libheif` library used by `sharp` which Next.js uses for image optimization can lead to remote code execution when AVIF files are optimized.

Until a fix has propagated, optimization of AVIF files is disabled.

Weakness classes: CWE-1395 (Dependency on Vulnerable Third-Party Component)

Source: GHSA-2xp9-vwfh-vxw4 · GitHub Advisory Database (CC-BY-4.0) — printed from a structured Sanity dataset. ← Back to the front page

ZéroJour prints itself from a Sanity dataset of real advisories (GitHub Advisory Database, CC-BY-4.0; CISA KEV). No scraping, no keyword search — headlines are typed fields, scores are numbers, fixes are versions. The newsroom composes, a human approves.