CVE-2026-3125
Published Mar 4, 2026A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, resulting from a path normalization bypass in the /cdn-cgi/image/ handler.…
- evidence mentions
- 4
- Buzz score
- 31.1