Vulnerabilities (CVE)

Filtered by vendor Cloudflare
Filtered by product Create-cloudflare
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-6087 2 Cloudflare, Opennextjs 2 Create-cloudflare, Opennext For Cloudflare 2025-08-06 N/A 9.1 CRITICAL
A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed unauthenticated users to proxy arbitrary remote content via the /_next/image endpoint. This issue allowed attackers to load remote resources from arbitrary hosts under the victim site’s domain for any site deployed using the Cloudflare adapter for Open Next.  For example: https: ...

Show More