Skip to main content

Vendor/product archive

opennextjs / opennext_for_cloudflare CVEs

Beta · best-effort

2 CVEs tagged to opennextjs / opennext_for_cloudflare0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-3125

Published Mar 4, 2026

A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, resulting from a path normalization bypass in the /cdn-cgi/image/ handler.…

CVSS 7.7 · High
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1