Next.js Unauthenticated RCE: CVE-2026-75604 Windows Path Traversal and the AVIF libheif Heap Overflow
Vercel's accelerated August 25, 2026 Next.js security release patched two unrelated critical, unauthenticated remote code execution flaws: a Windows-only path traversal (CVE-2026-75604, CVSS 9.0) with no workaround and a public PoC, and an AVIF image-decoding heap overflow (GHSA-2xp9-vwfh-vxw4, CVSS 4.0 9.5) inherited from the libheif library via the sharp dependency.