AI Briefing
KO

libheif RCE Vulnerability Discovered by Hacktron; Next.js and Vercel Issue Urgent Response

·2026.09.18 09:00

Key point

An RCE vulnerability in libheif was discovered, leading Next.js and Vercel to temporarily disable AVIF processing and the release of libheif v1.23.2.

1 / 2

Details

Hacktron discovered a remote code execution (RCE) vulnerability in the Next.js image optimization path. The investigation revealed that the vulnerability resides in the libheif library rather than Next.js itself, with malicious AVIF images being passed through sharp and libvips.

Emergency Response and Fixes

Vercel immediately disabled AVIF optimization at the platform level for centralized blocking. Next.js temporarily disabled AVIF functionality via a security release on August 25 for self-hosted environments, deemed the best interim measure while the libheif patch propagated. The RCE vulnerability was ultimately fixed with the release of libheif v1.23.2.

Surge in OSS Vulnerabilities

Open-source security threats are rapidly increasing in 2026. The CVE program has published over 35,000 vulnerabilities, and GitHub's private vulnerability reports surged from 500 per week in January to 3,000 per week in May. With LLMs accelerating vulnerability research, more upstream vulnerabilities like those in libheif are expected to emerge.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.